---
id: CVE-2026-93224
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  svcrdma: Fix unmatched rn_unregister on failed accept

  When svc_rdma_accept() takes the errout path before
  rpcrdma_rn_register() has succeeded, the existing cleanup blo…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  svcrdma: Fix unmatched rn_unregister on failed accept

  When svc_rdma_accept() takes the errout path before
  rpcrdma_rn_register() has succeeded, the existing cleanup blo…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cb3cba0ec372fa7c5f5f5c12990bef02e458ab86 <
    0335800071a6dfdf7d21d729b5e7d8fa98936211
  - >-
    Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 <
    5aabe070c00e5bdf4ab150fb5f72ad5f266d6241
  - >-
    Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 <
    45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2
  - >-
    Linux >= 8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932 <
    26190394c64c9429481fc88a4738f70bb92fb352
  - Linux d310955106c358c8e1ea682defd8e21af44a6cba
  - Linux >= 6.12.35 < 6.12.109
  - Linux >= 6.15.4 < 6.16
  - Linux 6.16
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T05:17:00.290'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93224'
references:
  - url: 'https://git.kernel.org/stable/c/0335800071a6dfdf7d21d729b5e7d8fa98936211'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/26190394c64c9429481fc88a4738f70bb92fb352'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5aabe070c00e5bdf4ab150fb5f72ad5f266d6241'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T15:45:56.665Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

svcrdma: Fix unmatched rn_unregister on failed accept

When svc_rdma_accept() takes the errout path before
rpcrdma_rn_register() has succeeded, the existing cleanup block
calls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditionally.
svcxprt_rdma is kzalloc'd, so on that path sc_rn.rn_index is 0 and
sc_rn.rn_done is NULL; the unregister therefore xa_erase()s another
caller's slot 0 and performs an unmatched kref_put() on the
rpcrdma_device's rd_kref.

The same errout also brackets the cleanup with svc_xprt_get()/
svc_xprt_put() around the kref_init() birth reference. The kref
goes 1 -> 2 -> 1 and never reaches 0, so the svcxprt_rdma (and the
net/ns_tracker it pinned) is leaked on every failed accept.

rpcrdma_rn_register() writes rn->rn_done last, only after xa_alloc()
and kref_get() have both succeeded, so rn_done == NULL is a natural
"never registered" sentinel. Guard rpcrdma_rn_unregister() with an
early return when rn_done is NULL, and clear rn_done before the
matching xa_erase() so a repeated unregister is also a no-op.

With that guard in place, the accept errout drops the kref_init()
birth reference via svc_xprt_put(), which dispatches svc_rdma_free().
Teardown of sc_qp, sc_sq_cq, sc_rq_cq, and sc_pd runs under existing
IS_ERR/NULL guards in svc_rdma_free(); sc_rn is covered by the new
rn_done sentinel; sc_cm_id is non-NULL on every errout path because
svc_rdma_accept() dereferences it above the first goto errout.

svc_xprt_free() drops the module reference associated with the freed
transport, and svc_handle_xprt() drops its pre-acquired reference
when ->xpo_accept() returns NULL. Take a replacement module reference
before svc_xprt_put() so the two module_put()s remain balanced.

The rn_done guard also covers svc_rdma_free()'s non-listener call
to rpcrdma_rn_unregister() for transports whose register attempt
failed or never ran.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
