---
id: CVE-2026-89536
title: 'SUNRPC: wait for in-flight client TLS handshake callback'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  SUNRPC: wait for in-flight client TLS handshake callback

  xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the
  lower transport before submitting the…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 <
    fb43997407bc17ee39bac81ab708101312e255f5
  - >-
    Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 <
    15431820f448e09f8029b670d5c82aa5917d4625
  - >-
    Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 <
    1de391e8b94e31b45c19c16dbf315e294810c7de
  - >-
    Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 <
    7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b
  - >-
    Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 <
    a89dd597458848b463d284b15e42a8078beeb046
  - Linux 6.5
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:00:45.076Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-89536'
references:
  - url: 'https://git.kernel.org/stable/c/fb43997407bc17ee39bac81ab708101312e255f5'
  - url: 'https://git.kernel.org/stable/c/15431820f448e09f8029b670d5c82aa5917d4625'
  - url: 'https://git.kernel.org/stable/c/1de391e8b94e31b45c19c16dbf315e294810c7de'
  - url: 'https://git.kernel.org/stable/c/7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b'
  - url: 'https://git.kernel.org/stable/c/a89dd597458848b463d284b15e42a8078beeb046'
tags:
  - cve.org
epss: 0.00671
epssPercentile: 0.49863
ingestedAt: '2026-09-14T15:23:07.452Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: wait for in-flight client TLS handshake callback

xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the
lower transport before submitting the handshake request. On timeout or
signal, the synchronous waiter drops that reference after calling
tls_handshake_cancel().

handshake_req_cancel() returns false when handshake_complete() has
already marked the request complete. In that case the completion callback
can still be running, so dropping the callback-owned reference in the
waiter can free the lower transport before xs_tls_handshake_done() stores
xprt_err or drops its own reference.

If cancellation loses to completion, wait until xs_tls_handshake_done()
signals handshake_done and let the callback release its reference. This
mirrors the server-side handshake lifetime handling and keeps the timeout
or signal return value unchanged.

## Affected

- `Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 < fb43997407bc17ee39bac81ab708101312e255f5`
- `Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 15431820f448e09f8029b670d5c82aa5917d4625`
- `Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 1de391e8b94e31b45c19c16dbf315e294810c7de`
- `Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 < 7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b`
- `Linux >= 75eb6af7acdf566c68d61e98e67ee2f235201c02 < a89dd597458848b463d284b15e42a8078beeb046`
- `Linux 6.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
