{"id":"CVE-2026-89742","title":"kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free() (CVE-2026-89742)","summary":"A flaw was found in the Linux kernel. A local user could exploit a use-after-free vulnerability in the `dma_req_free()` function within the RapidIO mport character device interface. This flaw occurs when the `dma_req_free()` function attem…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Linux","affected":["Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < 00c5ed913b0dc563fbeb8a97ea8916c03bbbbf6a","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < fc79c07cdcde02c5b17633d78777de6ac2c14b29","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < 26ccfe7d69e27b0d933ae0a64a23a0cb9b9a85a6","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < bd8881c24a9520f9c3d3e855d866197f63e471a7","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < 9a9929ec875ff20922c90c96fd544ae8a2a61a8d","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < e6e925cc1f8067c65c7bec3da50a0ead3b3ef4e0","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < 211c68d817a3d9dc14c0026a59da7cac30f8147e","Linux >= e8de370188d098bb49483c287b44925957c3c9b6 < 5cbef379a94b161726c5f504598bf4791d45cedc","Linux 4.6"],"published":"2026-09-11","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:28:13+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89742.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89742.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89742"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532155"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89742"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89742"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89742.mbox"},{"url":"https://git.kernel.org/stable/c/00c5ed913b0dc563fbeb8a97ea8916c03bbbbf6a"},{"url":"https://git.kernel.org/stable/c/fc79c07cdcde02c5b17633d78777de6ac2c14b29"},{"url":"https://git.kernel.org/stable/c/26ccfe7d69e27b0d933ae0a64a23a0cb9b9a85a6"},{"url":"https://git.kernel.org/stable/c/bd8881c24a9520f9c3d3e855d866197f63e471a7"},{"url":"https://git.kernel.org/stable/c/9a9929ec875ff20922c90c96fd544ae8a2a61a8d"},{"url":"https://git.kernel.org/stable/c/e6e925cc1f8067c65c7bec3da50a0ead3b3ef4e0"},{"url":"https://git.kernel.org/stable/c/211c68d817a3d9dc14c0026a59da7cac30f8147e"},{"url":"https://git.kernel.org/stable/c/5cbef379a94b161726c5f504598bf4791d45cedc"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00159,"epssPercentile":0.05512,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.449Z","slug":"CVE-2026-89742","body":"## Overview\n\nA flaw was found in the Linux kernel. A local user could exploit a use-after-free vulnerability in the `dma_req_free()` function within the RapidIO mport character device interface. This flaw occurs when the `dma_req_free()` function attempts to dereference a freed object after dropping the last reference to a mapping. Successful exploitation of this vulnerability could lead to arbitrary code execution or a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89742.json)\n\n**kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-21.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208953,"id":"CVE-2026-89742","ts":1790062298868,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208952,"id":"CVE-2026-89742","ts":1790062298868,"field":"severity","old":"high","new":"medium"},{"seq":183831,"id":"CVE-2026-89742","ts":1789356677590,"field":"cvss","old":"7.8","new":"6.4"},{"seq":183830,"id":"CVE-2026-89742","ts":1789356677590,"field":"severity","old":"high","new":"medium"},{"seq":153626,"id":"CVE-2026-89742","ts":1789285351611,"field":"cvss","old":null,"new":"7.8"},{"seq":153625,"id":"CVE-2026-89742","ts":1789285351611,"field":"severity","old":"none","new":"high"},{"seq":147676,"id":"CVE-2026-89742","ts":1789270211841,"field":"cvss","old":null,"new":"6.4"},{"seq":147675,"id":"CVE-2026-89742","ts":1789270211841,"field":"severity","old":"none","new":"medium"},{"seq":109430,"id":"CVE-2026-89742","ts":1789183731885,"field":"cvss","old":null,"new":"6.4"},{"seq":109429,"id":"CVE-2026-89742","ts":1789183731885,"field":"severity","old":"none","new":"medium"}]}