# CVE-2026-89543

## Summary

- **CVE ID:** CVE-2026-89543
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir

Normal client creation goes through rpc_setup_pipedir(), which records
clnt->pipefs_sb, but the mount-event path in __rpc_clnt_handle_event()
calls rpc_setup_pipedir_sb() directly and never refreshes that field.
The umount path also removes the directory without clearing
clnt->pipefs_sb.

After a late pipefs mount or any remount, rpc_clnt_remove_pipedir()
compares the current superblock against a stale pipefs_sb pointer and
skips cleanup, leaving pipefs dentries whose inode private data still
points at a freed rpc_clnt, leading to a potential use-after-free during
subsequent rpc_info_open() or rpc_show_info() calls.

Fix this by properly updating clnt->pipefs_sb upon mount events and
clearing it during unmount or failure paths.

## Affected Products

- Linux — Linux (bfca5fb4e97c46503ddfc582335917b0cc228264)
- Linux — Linux (17866066b8ac1cc38fb449670bc15dc9fee4b40a)
- Linux — Linux (7d61d1da2ed1f682c41cae0c8d4719cdaccee5c5)
- Linux — Linux (dedf2a0eb9448ae73b270743e6ea9b108189df46)
- Linux — Linux (194454afa6aa9d6ed74f0c57127bc8beb27c20df)
- Linux — Linux (7749fd2dbef72a52b5c9ffdbf877691950ed4680)
- Linux — Linux (1cdb52ffd6600a37bd355d8dce58ecd03e55e618)
- Linux — Linux (cc2e7ebbeb1d0601f7f3c8d93b78fcc03a95e44a)
- Linux — Linux (4.19.318)
- Linux — Linux (5.4.280)
- Linux — Linux (5.10.202)
- Linux — Linux (5.15.140)
- Linux — Linux (6.1.64)
- Linux — Linux (6.5.13)
- Linux — Linux (6.6.3)
- Linux — Linux (6.7)
- Linux — Linux (0)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/e769fcde3cc73e847b1eb3acd40c04a291cb0c0c)
- [CNA](https://git.kernel.org/stable/c/cdf7a233cb94774b0e7df42d9157077983f5022c)
- [CNA](https://git.kernel.org/stable/c/932a8cf6abb2b2f8677b79153a823108d8861fe2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._