Executive brief
The Linux kernel's RapidIO mport character device driver contains a use-after-free vulnerability in memory management code. An attacker with local access to the RapidIO device interface can trigger a crash or potentially execute code by freeing a memory mapping object while a mutex (lock) associated with it is still being accessed. This could disrupt system stability or allow privilege escalation on affected systems.
Technical details
The vulnerability is a use-after-free in the dma_req_free() function within drivers/rapidio/devices/rio_mport_cdev.c. The root cause is that the code acquires a mutex through req->map, drops the reference via kref_put() which can trigger mport_release_mapping() to free the mapping object, then attempts to unlock the mutex via the now-freed req->map pointer. The attack vector is the RapidIO mport character device interface, which is reachable from userspace. An attacker does not require special privileges to access this interface. The fix caches both the mapping and device pointers before the reference drop, clears req->map while holding the mutex, and uses the cached pointers for unlocking, preventing the use-after-free condition.
Affected products
- Linux Linux kernel all versions with RapidIO mport_cdev driver (since e8de370188d0)
Timeline
- 2026-09-11: disclosed: CVE-2026-89742 published
- 2026-09-14: patched: Fix committed to Linux stable tree
- 2026-07-24: other: Patch authored by James Kim