๐Ÿ” CVE Alert

CVE-2026-89536

CRITICAL 9.8

SUNRPC: wait for in-flight client TLS handshake callback

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
75eb6af7acdf566c68d61e98e67ee2f235201c02 < fb43997407bc17ee39bac81ab708101312e255f5 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 15431820f448e09f8029b670d5c82aa5917d4625 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 1de391e8b94e31b45c19c16dbf315e294810c7de 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b 75eb6af7acdf566c68d61e98e67ee2f235201c02 < a89dd597458848b463d284b15e42a8078beeb046
Linux / Linux
6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fb43997407bc17ee39bac81ab708101312e255f5 git.kernel.org: https://git.kernel.org/stable/c/15431820f448e09f8029b670d5c82aa5917d4625 git.kernel.org: https://git.kernel.org/stable/c/1de391e8b94e31b45c19c16dbf315e294810c7de git.kernel.org: https://git.kernel.org/stable/c/7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b git.kernel.org: https://git.kernel.org/stable/c/a89dd597458848b463d284b15e42a8078beeb046