---
id: CVE-2026-89784
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6

  rpcb_register_inet4() and rpcb_register_inet6() store the result of
  rpc_sockaddr2uaddr() into …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6

  rpcb_register_inet4() and rpcb_register_inet6() store the result of
  rpc_sockaddr2uaddr() into …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    04441b792ec40eb66349b5fab34b6a2090b5b2dd
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    5a51c49ddb37b883566874aecc66bc5a2e617a96
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    4a6095de8cb1858e05bdf70b3e7d6d7645c25041
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    12bf3e0182ccdaf3b412756a756d3944a7dacaa9
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    4e01022974355732e748ec8ebc97c558cb624ffe
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    cda4aacfb0bbf5c0f90fd0b42c72c749635d1368
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    eb476289c12cc22c8766f8a84eeb7ab46c4e8fb6
  - >-
    Linux >= d77385f23830ee6c400569bac8b37e6eb3b7d360 <
    fd22370226a0d8109045d0831fd5aaadee921693
  - Linux 3.2
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T09:17:09.060'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89784'
references:
  - url: 'https://git.kernel.org/stable/c/04441b792ec40eb66349b5fab34b6a2090b5b2dd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/12bf3e0182ccdaf3b412756a756d3944a7dacaa9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4a6095de8cb1858e05bdf70b3e7d6d7645c25041'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4e01022974355732e748ec8ebc97c558cb624ffe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5a51c49ddb37b883566874aecc66bc5a2e617a96'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cda4aacfb0bbf5c0f90fd0b42c72c749635d1368'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb476289c12cc22c8766f8a84eeb7ab46c4e8fb6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd22370226a0d8109045d0831fd5aaadee921693'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T08:52:29.593Z'
epss: 0.0021
epssPercentile: 0.1154
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6

rpcb_register_inet4() and rpcb_register_inet6() store the result of
rpc_sockaddr2uaddr() into map->r_addr without checking it for NULL.
rpc_sockaddr2uaddr() returns NULL when its final kstrdup() fails, and
the unchecked NULL is then carried into the synchronous RPCBPROC_SET
encode path: rpcb_register_call() -> rpc_call_sync() ->
rpcb_enc_getaddr() -> encode_rpcb_string(), whose first statement is
strlen(string), dereferencing NULL and oopsing the kernel.

The crash reproduces under failslab on v6.12; with KASAN the NULL
dereference surfaces as a fault on the shadow of address zero:

 Oops: general protection fault, probably for non-canonical address
       0xdffffc0000000000 [#1] PREEMPT SMP KASAN
 RIP: 0010:strlen (lib/string.c:409)
 Call Trace:
  encode_rpcb_string (net/sunrpc/rpcb_clnt.c:890)
  rpcb_enc_getaddr (net/sunrpc/rpcb_clnt.c:910)
  rpcauth_wrap_req_encode (net/sunrpc/auth.c:745)
  call_encode (net/sunrpc/clnt.c:1966)
  __rpc_execute (net/sunrpc/sched.c:952)
  rpc_run_task (net/sunrpc/clnt.c:1243)
  rpc_call_sync (net/sunrpc/clnt.c:1272)
  rpcb_v4_register (net/sunrpc/rpcb_clnt.c:500)
  svc_generic_rpcbind_set
  nfsd_rpcbind_set
  svc_register
  svc_setup_socket
  svc_addsock
  write_ports
  nfsctl_transaction_write
  vfs_write

The crash is reachable when an in-kernel RPC service (nfsd, lockd,
nfs-callback) registers with the local rpcbind under enough memory
pressure for the small GFP_KERNEL kstrdup() in rpc_sockaddr2uaddr() to
fail. The asynchronous getport path already handles this exact failure
mode by returning -ENOMEM; only the two register helpers omit the check.

Mirror that handling: bail out with -ENOMEM when rpc_sockaddr2uaddr()
returns NULL, before the address is fed into the encoder.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
