CVE-2026-89536
CVE CVE-2026-89536EUVD EUVD-2026-76442Published 2026-09-11T19:44:14.000ZLast changed 2026-09-14T12:00:45.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.12.109; 75eb6af7acdf566c68d61e98e67ee2f235201c02 <a89dd597458848b463d284b15e42a8078beeb046; 75eb6af7acdf566c68d61e98e67ee2f235201c02 <1de391e8b94e31b45c19c16dbf315e294810c7de; patch: 6.6.157; patch: 7.2.4; 6.5; 75eb6af7acdf566c68d61e98e67ee2f235201c02 <15431820f448e09f8029b670d5c82aa5917d4625; patch: 7.3-rc1; patch: 0; patch: 6.18.50; 75eb6af7acdf566c68d61e98e67ee2f235201c02 <7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b; 75eb6af7acdf566c68d61e98e67ee2f235201c02 <fb43997407bc17ee39bac81ab708101312e255f5
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.