{"id":"CVE-2026-89507","summary":"RDMA/ucma: Lock the handler in ucma_write_cm_event()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Lock the handler in ucma_write_cm_event()\n\nctx-\u003efile may only be changed under the handler lock and the xa_lock, which\nis what stops uevents being queued for a ctx while ucma_migrate_id() moves\nit to another file.  The CM core takes that lock before invoking\nucma_event_handler(), but the write() paths that queue uevents themselves\ndo not.\n\nucma_write_cm_event() re-reads ctx-\u003efile for each of its four dereferences,\nso ucma_migrate_id() can swap it mid-sequence:\n\n\tmutex_lock(&ctx-\u003efile-\u003emut);\t\t\t/* file A */\n\tlist_add_tail(&uevent-\u003elist, &ctx-\u003efile-\u003eevent_list);\t/* file B */\n\tmutex_unlock(&ctx-\u003efile-\u003emut);\t\t\t/* file B */\n\twake_up_interruptible(&ctx-\u003efile-\u003epoll_wait);\t/* file B */\n\nThe window is the mutex_lock() itself: the writer sleeps in it while the\nmigration reassigns ctx-\u003efile.  The list_add_tail() then runs on file B's\nevent_list holding only file A's mutex:\n\n  list_add corruption. prev-\u003enext should be next (ffff888101320f30),\n    but was ffff88814a08c418. (prev=ffff88814a075c18).\n  kernel BUG at lib/list_debug.c:32!\n  Call Trace:\n   ucma_write_cm_event+0x36e/0x5e0\n\nand file A's mut is left held forever, wedging its next writer in D state.\nThe uevent is also stranded on a list ucma_cleanup_ctx_events() will not\nwalk, so it outlives its context.  /dev/infiniband/rdma_cm is 0666 and no\nRDMA device is involved, so an unprivileged user reaches all of this.\n\nTake the handler lock, as ucma_cleanup_mc_events() does; ctx-\u003ecm_id is\npinned by the ucma_get_ctx() reference.","modified":"2026-09-13T03:47:18.556488677Z","published":"2026-09-11T19:43:54.013Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0be1955040a2eceed0ecfc387fdc92305411d273"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4f8bb11dd2ff365e7cff1c9964ab4607292d364e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f4cc21c6a8e9d392871477f9fd98d68e5ad80272"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89507"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5"},{"fixed":"4f8bb11dd2ff365e7cff1c9964ab4607292d364e"},{"fixed":"0be1955040a2eceed0ecfc387fdc92305411d273"},{"fixed":"f4cc21c6a8e9d392871477f9fd98d68e5ad80272"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89507.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.18.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89507.json"}}],"schema_version":"1.9.0"}