CVE-2026-89543: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir Normal client creation goes through rpc_setup_pipedir(), which records clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event() calls rpc_setup_pipedir_sb() directly and never refreshes that field. The umount path also removes the directory without clearing clnt->pipefs_sb. After a late pipefs mount or any remount, rpc_clnt_remove_pipedir() compares the current superblock against a stale pipefs_sb pointer and skips cleanup, leaving pipefs dentries whose inode private data still points at a freed rpc_clnt, leading to a potential use-after-free during subsequent rpc_info_open() or rpc_show_info() calls. Fix this by properly updating clnt->pipefs_sb upon mount events and clearing it during unmount or failure paths.
Affected products
- Linux Linux: from 4.19.318, before 4.20 (fixed in 4.20); from 5.4.280, before 5.5 (fixed in 5.5); from 5.10.202, before 5.11 (fixed in 5.11); from 5.15.140, before 5.16 (fixed in 5.16); from 6.1.64, before 6.2 (fixed in 6.2); from 6.5.13, before 6.6 (fixed in 6.6); …
Published 2026-09-11. Last modified 2026-09-21.