# CVE-2026-89547

## Summary

- **CVE ID:** CVE-2026-89547
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: Check svc pool percpu counter allocation

__svc_create() initializes three per-pool percpu_counter stats and
ignores every return value. On SMP, percpu_counter_init() fails when
__alloc_percpu_gfp() cannot satisfy the allocation, leaving the failed
counter with fbc->counters == NULL and its embedded raw_spinlock_t,
list_head, and count never initialized. __svc_create() returns the
half-constructed svc_serv to nfsd, lockd, or the NFS callback service
anyway.

Once that service is live, the hot-path increments in
svc_xprt_enqueue(), svc_handle_xprt(), and
svc_pool_wake_idle_thread() reach a counter whose backing pointer is
NULL. The pointer is a per-cpu offset, so the access does not fault:
it resolves to offset zero of the current CPU's per-cpu area and
silently corrupts whatever variable lives there. A
/proc/fs/nfsd/pool_stats read walks the same NULL per-cpu storage and
returns garbage, and on CONFIG_DEBUG_SPINLOCK or lockdep it splats on
the never-initialized lock.

Creating the broken service requires a percpu allocation failure during
RPC server startup, so it is reachable only by a local administrator
under memory pressure or fault injection; a remote peer cannot induce
the bad state on its own.

Check each percpu_counter_init() return value in __svc_create() and
fail when an allocation fails, unwinding the counters already set up
in the current pool and in every pool initialized before it. A
discrete percpu_counter_destroy() per counter at teardown frees each
per-cpu allocation exactly once.

## Affected Products

- Linux — Linux (ccf08bed6e7a80519569456edd2ea21b7b1701c6)
- Linux — Linux (6.3)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/3a2b7649de76376a69f1d3ed2a539fb15907cd4d)
- [CNA](https://git.kernel.org/stable/c/bd1ef2cfb44d72b7aa6943e87b206eb0e30fbd0c)
- [CNA](https://git.kernel.org/stable/c/b541a15046976e481618726cc23db0fb22d576db)
- [CNA](https://git.kernel.org/stable/c/43e11e164704dde975c9edb370de1a06bec67270)
- [CNA](https://git.kernel.org/stable/c/57ac7d899409b0a9b768cf417e3bb86bcca3d4c6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._