{"id":"CVE-2026-93224","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Fix unmatched rn_unregister on failed accept\n\nWhen svc_rdma_accept() takes the errout path before\nrpcrdma_rn_register() has succeeded, the existing cleanup blo…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Fix unmatched rn_unregister on failed accept\n\nWhen svc_rdma_accept() takes the errout path before\nrpcrdma_rn_register() has succeeded, the existing cleanup blo…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= cb3cba0ec372fa7c5f5f5c12990bef02e458ab86 < 0335800071a6dfdf7d21d729b5e7d8fa98936211","Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 < 5aabe070c00e5bdf4ab150fb5f72ad5f266d6241","Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 < 45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2","Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 < 26190394c64c9429481fc88a4738f70bb92fb352","Linux d310955106c358c8e1ea682defd8e21af44a6cba","Linux >= 6.12.35 < 6.12.109","Linux >= 6.15.4 < 6.16","Linux 6.16"],"published":"2026-09-24","updated":"2026-09-25","sourceUpdated":"2026-09-25T05:17:00.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93224","references":[{"url":"https://git.kernel.org/stable/c/0335800071a6dfdf7d21d729b5e7d8fa98936211","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26190394c64c9429481fc88a4738f70bb92fb352","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aabe070c00e5bdf4ab150fb5f72ad5f266d6241","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T15:45:56.665Z","slug":"CVE-2026-93224","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Fix unmatched rn_unregister on failed accept\n\nWhen svc_rdma_accept() takes the errout path before\nrpcrdma_rn_register() has succeeded, the existing cleanup block\ncalls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditionally.\nsvcxprt_rdma is kzalloc'd, so on that path sc_rn.rn_index is 0 and\nsc_rn.rn_done is NULL; the unregister therefore xa_erase()s another\ncaller's slot 0 and performs an unmatched kref_put() on the\nrpcrdma_device's rd_kref.\n\nThe same errout also brackets the cleanup with svc_xprt_get()/\nsvc_xprt_put() around the kref_init() birth reference. The kref\ngoes 1 -> 2 -> 1 and never reaches 0, so the svcxprt_rdma (and the\nnet/ns_tracker it pinned) is leaked on every failed accept.\n\nrpcrdma_rn_register() writes rn->rn_done last, only after xa_alloc()\nand kref_get() have both succeeded, so rn_done == NULL is a natural\n\"never registered\" sentinel. Guard rpcrdma_rn_unregister() with an\nearly return when rn_done is NULL, and clear rn_done before the\nmatching xa_erase() so a repeated unregister is also a no-op.\n\nWith that guard in place, the accept errout drops the kref_init()\nbirth reference via svc_xprt_put(), which dispatches svc_rdma_free().\nTeardown of sc_qp, sc_sq_cq, sc_rq_cq, and sc_pd runs under existing\nIS_ERR/NULL guards in svc_rdma_free(); sc_rn is covered by the new\nrn_done sentinel; sc_cm_id is non-NULL on every errout path because\nsvc_rdma_accept() dereferences it above the first goto errout.\n\nsvc_xprt_free() drops the module reference associated with the freed\ntransport, and svc_handle_xprt() drops its pre-acquired reference\nwhen ->xpo_accept() returns NULL. Take a replacement module reference\nbefore svc_xprt_put() so the two module_put()s remain balanced.\n\nThe rn_done guard also covers svc_rdma_free()'s non-listener call\nto rpcrdma_rn_unregister() for transports whose register attempt\nfailed or never ran.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210509,"id":"CVE-2026-93224","ts":1790316054460,"field":"cvss","old":null,"new":"8.1"},{"seq":210508,"id":"CVE-2026-93224","ts":1790316054460,"field":"severity","old":"none","new":"high"}]}