PT-2026-93390 · Linux · Linux Kernel
CVE-2026-89784
·
Published
2026-09-16
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel version 6.12
Description
In the SUNRPC component, the functions
rpcb register inet4() and rpcb register inet6() fail to check the return value of rpc sockaddr2uaddr() before storing it in map->r addr. When rpc sockaddr2uaddr() returns NULL due to a kstrdup() failure under memory pressure, this NULL value is passed through the synchronous RPCBPROC SET encode path: rpcb register call() -> rpc call sync() -> rpcb enc getaddr() -> encode rpcb string(). The encode rpcb string() function then calls strlen() on the NULL pointer, leading to a kernel oops and a general protection fault. This issue is reachable when in-kernel RPC services such as nfsd, lockd, or nfs-callback register with the local rpcbind during periods of high memory pressure.Recommendations
Update the Linux kernel to a version where the return value of
rpc sockaddr2uaddr() is properly checked in rpcb register inet4() and rpcb register inet6() to ensure the system bails out with -ENOMEM when a NULL value is returned.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel