{"id":"CVE-2026-89549","title":"sunrpc: route to a populated pool in svc_pool_for_cpu()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: route to a populated pool in svc_pool_for_cpu()\n\nsvc_set_num_threads() spreads the requested threads evenly across the\nservice's pools (base = nrservs / sv_nrpo…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 9accc25e5af0bac8479f6054e674b2c593c45281","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 6f66d38e2a6c78d48723ea17ad86135ec80ca24b","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < edb20e8c03aebacb409968c99d046f509c6c485a","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 011479cf9a7657d4a3e7cc42a784ac63df594170","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 9d04d64ad192439835ed9884d767353061c3ed6f","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 8f766d2d0b4dabf54f8b35812df2b4f481d13316","Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < f6310491c4cdb88af73aa551ec9df1f10a90c709","Linux 2.6.19"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:00:52.566Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-89549","references":[{"url":"https://git.kernel.org/stable/c/9accc25e5af0bac8479f6054e674b2c593c45281"},{"url":"https://git.kernel.org/stable/c/6f66d38e2a6c78d48723ea17ad86135ec80ca24b"},{"url":"https://git.kernel.org/stable/c/d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f"},{"url":"https://git.kernel.org/stable/c/edb20e8c03aebacb409968c99d046f509c6c485a"},{"url":"https://git.kernel.org/stable/c/011479cf9a7657d4a3e7cc42a784ac63df594170"},{"url":"https://git.kernel.org/stable/c/9d04d64ad192439835ed9884d767353061c3ed6f"},{"url":"https://git.kernel.org/stable/c/8f766d2d0b4dabf54f8b35812df2b4f481d13316"},{"url":"https://git.kernel.org/stable/c/f6310491c4cdb88af73aa551ec9df1f10a90c709"}],"tags":["cve.org"],"epss":0.00716,"epssPercentile":0.52335,"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89549","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: route to a populated pool in svc_pool_for_cpu()\n\nsvc_set_num_threads() spreads the requested threads evenly across the\nservice's pools (base = nrservs / sv_nrpools).  When a service runs\nfewer threads than it has pools -- e.g. an nfsd configured with fewer\nthreads than the host has NUMA nodes while running in \"pernode\" or\n\"percpu\" mode -- the trailing pools are left with no threads at all.\n\nsvc_xprt_enqueue() selects a pool from the CPU servicing the transport,\nqueues the transport on that pool's sp_xprts, and only wakes a thread\nfrom the same pool.  Each thread services exclusively its own pool, so a\ntransport that lands on a threadless pool is enqueued on sp_xprts and\nnever picked up: the connection hangs indefinitely.\n\nHave svc_pool_for_cpu() skip pools that currently have no threads,\nfalling back to the next populated pool.  This trades NUMA locality for\na guarantee that the work is actually serviced.  sp_nrthreads is only\nupdated under the service mutex; the lockless read here is a best-effort\nrouting hint, so annotate it with data_race().\n\n## Affected\n\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 9accc25e5af0bac8479f6054e674b2c593c45281`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 6f66d38e2a6c78d48723ea17ad86135ec80ca24b`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < d79d7b9e8acbb53e2d60f6b24afc13e2f15e691f`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < edb20e8c03aebacb409968c99d046f509c6c485a`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 011479cf9a7657d4a3e7cc42a784ac63df594170`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 9d04d64ad192439835ed9884d767353061c3ed6f`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < 8f766d2d0b4dabf54f8b35812df2b4f481d13316`\n- `Linux >= bfd241600a3b0db4fe43c859f1460d0a958d924a < f6310491c4cdb88af73aa551ec9df1f10a90c709`\n- `Linux 2.6.19`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":197937,"id":"CVE-2026-89549","ts":1789384321040,"field":"cvss","old":"5.9","new":"7.5"},{"seq":197936,"id":"CVE-2026-89549","ts":1789384321040,"field":"severity","old":"medium","new":"high"},{"seq":183481,"id":"CVE-2026-89549","ts":1789356675543,"field":"cvss","old":"7.5","new":"5.9"},{"seq":183480,"id":"CVE-2026-89549","ts":1789356675543,"field":"severity","old":"high","new":"medium"},{"seq":153354,"id":"CVE-2026-89549","ts":1789285350171,"field":"cvss","old":null,"new":"7.5"},{"seq":153353,"id":"CVE-2026-89549","ts":1789285350171,"field":"severity","old":"none","new":"high"},{"seq":147225,"id":"CVE-2026-89549","ts":1789270202565,"field":"cvss","old":null,"new":"5.9"},{"seq":147224,"id":"CVE-2026-89549","ts":1789270202565,"field":"severity","old":"none","new":"medium"},{"seq":108978,"id":"CVE-2026-89549","ts":1789183729813,"field":"cvss","old":null,"new":"5.9"},{"seq":108977,"id":"CVE-2026-89549","ts":1789183729813,"field":"severity","old":"none","new":"medium"}]}