{"id":"CVE-2026-89510","summary":"RDMA/cxgb4: Cancel reg_work before freeing device on remove","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: Cancel reg_work before freeing device on remove\n\nc4iw_uld_state_change() queues reg_work to register the RDMA device.\nc4iw_remove() can free ctx-\u003edev while this work is pending or running,\nleaving c4iw_register_device() accessing the freed device.\n\nCancel reg_work before removing the device.  The registration work can\ntear down ctx-\u003edev when registration fails, so do not unregister or\ndeallocate it again in that case.\n\nThis issue was found by an in-house static analysis tool.","modified":"2026-09-13T03:47:18.752071756Z","published":"2026-09-11T19:43:55.989Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89510.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/320e5258a53af0abc5abd9eb01519a48bab2dee8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/85f438382a865a4dc4c50e6b884310bb2b60fc4d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a7100601aa1a39f799a566acce10db20eaf4b7f2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fe9c591026c576d8b1f72aab5e4cd67350530763"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89510.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89510"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5"},{"fixed":"fe9c591026c576d8b1f72aab5e4cd67350530763"},{"fixed":"85f438382a865a4dc4c50e6b884310bb2b60fc4d"},{"fixed":"320e5258a53af0abc5abd9eb01519a48bab2dee8"},{"fixed":"a7100601aa1a39f799a566acce10db20eaf4b7f2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89510.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89510.json"}}],"schema_version":"1.9.0"}