PT-2026-90202 · Linux · Linux

CVE-2026-89486

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
ipmi: Fix use-after-free of cmd rcvr in ipmi destroy user()
Commit 9e91f8a6c868 ("ipmi:msghandler: Remove srcu for the ipmi interfaces list") dropped the synchronize rcu() between unlinking the command receivers from intf->cmd rcvrs and freeing them, updating only the comment that explains why the barrier is needed.
The cmd rcvrs list is still traversed under plain RCU: find cmd rcvr() walks it inside rcu read lock(), and handle ipmb get msg cmd() borrows rcvr->user from that lookup within the same read-side section. Without the grace period, ipmi destroy user() can kfree() a cmd rcvr while a reader still holds a pointer to it, causing a use-after-free.
The rework only made srcu unnecessary for the interfaces list; the cmd rcvrs list still relies on plain RCU. Restore the synchronize rcu() before freeing the receivers.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-89486

Produtos afetados

Linux