Executive brief
The Linux kernel IPMI (Intelligent Platform Management Interface) subsystem contains a use-after-free vulnerability in the command receiver cleanup code. When a user is destroyed, the kernel can free memory that is still being accessed by concurrent readers, potentially leading to kernel crashes or data corruption. This affects systems using IPMI for hardware management and monitoring.
Technical details
A use-after-free vulnerability exists in the _ipmi_destroy_user() function in drivers/char/ipmi/ipmi_msghandler.c. A prior refactoring commit removed a synchronize_rcu() call that was necessary to ensure safe cleanup of the cmd_rcvrs list. The cmd_rcvrs list is traversed under RCU read-side critical sections (e.g., in find_cmd_rcvr()), but without the grace period, kfree() can deallocate a cmd_rcvr structure while concurrent readers still hold pointers to it. The fix adds back the synchronize_rcu() call before freeing receivers to ensure all RCU read-side critical sections have completed. No authentication or special privileges are required; the vulnerability is triggered during normal user teardown operations.
Affected products
- Linux Linux Kernel affected versions include kernels with the vulnerable refactoring commit 9e91f8a6c868 and later
Timeline
- 2026-09-11: disclosed: CVE-2026-89486 published
- 2026-08-25: patched: Fix commit 05ec76cfbce653e07cec19b9b8b20e33449d5d87 merged