{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "a3c9d0fcd3715541bbf97da2ddde9d032e2fe6d5"
            },
            {
              "fixed": "4f8bb11dd2ff365e7cff1c9964ab4607292d364e"
            },
            {
              "fixed": "0be1955040a2eceed0ecfc387fdc92305411d273"
            },
            {
              "fixed": "f4cc21c6a8e9d392871477f9fd98d68e5ad80272"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.18.0"
            },
            {
              "fixed": "6.18.50"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Lock the handler in ucma_write_cm_event()\n\nctx-\u003efile may only be changed under the handler lock and the xa_lock, which\nis what stops uevents being queued for a ctx while ucma_migrate_id() moves\nit to another file.  The CM core takes that lock before invoking\nucma_event_handler(), but the write() paths that queue uevents themselves\ndo not.\n\nucma_write_cm_event() re-reads ctx-\u003efile for each of its four dereferences,\nso ucma_migrate_id() can swap it mid-sequence:\n\n\tmutex_lock(\u0026ctx-\u003efile-\u003emut);\t\t\t/* file A */\n\tlist_add_tail(\u0026uevent-\u003elist, \u0026ctx-\u003efile-\u003eevent_list);\t/* file B */\n\tmutex_unlock(\u0026ctx-\u003efile-\u003emut);\t\t\t/* file B */\n\twake_up_interruptible(\u0026ctx-\u003efile-\u003epoll_wait);\t/* file B */\n\nThe window is the mutex_lock() itself: the writer sleeps in it while the\nmigration reassigns ctx-\u003efile.  The list_add_tail() then runs on file B's\nevent_list holding only file A's mutex:\n\n  list_add corruption. prev-\u003enext should be next (ffff888101320f30),\n    but was ffff88814a08c418. (prev=ffff88814a075c18).\n  kernel BUG at lib/list_debug.c:32!\n  Call Trace:\n   ucma_write_cm_event+0x36e/0x5e0\n\nand file A's mut is left held forever, wedging its next writer in D state.\nThe uevent is also stranded on a list ucma_cleanup_ctx_events() will not\nwalk, so it outlives its context.  /dev/infiniband/rdma_cm is 0666 and no\nRDMA device is involved, so an unprivileged user reaches all of this.\n\nTake the handler lock, as ucma_cleanup_mc_events() does; ctx-\u003ecm_id is\npinned by the ucma_get_ctx() reference.",
  "id": "CVE-2026-89507",
  "modified": "2026-09-15T03:30:57.007203586Z",
  "published": "2026-09-11T19:43:54.013Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0be1955040a2eceed0ecfc387fdc92305411d273"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4f8bb11dd2ff365e7cff1c9964ab4607292d364e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f4cc21c6a8e9d392871477f9fd98d68e5ad80272"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89507.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89507"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "RDMA/ucma: Lock the handler in ucma_write_cm_event()"
}