Executive brief
The Linux kernel's RDMA transport service (svcrdma) used by NFS and other network services has a resource leak when the listener creation fails. A reference to the network namespace is not properly released, and module reference counts become unbalanced, potentially leading to resource exhaustion or module unload issues over time if this error path is triggered repeatedly.
Technical details
The vulnerability is a resource leak in svc_rdma_create() in the RDMA transport code. When svc_rdma_create_listen_id() fails, the function was calling kfree(cma_xprt) directly, bypassing the proper cleanup path through svc_xprt_free(). This left a net namespace reference acquired by svc_xprt_init() unreleased. Additionally, module reference counts became unbalanced because svc_xprt_free() performs a module_put(), but the caller _svc_xprt_create() also does a module_put() on xpo_create failure. The fix replaces kfree() with svc_xprt_put() and adds a compensating __module_get() to balance the reference count. The vulnerable code path is triggered when the RDMA listener creation fails, which requires network reachability and RDMA support but no special authentication.
Affected products
- Linux Linux kernel multiple versions (net/sunrpc/xprtrdma affected)
Timeline
- 2026-09-11: disclosed: CVE-2026-89527 published on NVD
- 2026-05-27: patched: Fix committed upstream by Chuck Lever (commit e346ef7bcb137f50c49f969330ab7dcf64ea1654)
- 2026-09-07: patched: Fix included in stable kernel releases by Greg Kroah-Hartman