{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "cb3cba0ec372fa7c5f5f5c12990bef02e458ab86"
            },
            {
              "fixed": "0335800071a6dfdf7d21d729b5e7d8fa98936211"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "8ac6fcae5dc0e801f1c82a83f5ae2c0a4db19932"
            },
            {
              "fixed": "5aabe070c00e5bdf4ab150fb5f72ad5f266d6241"
            },
            {
              "fixed": "45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2"
            },
            {
              "fixed": "26190394c64c9429481fc88a4738f70bb92fb352"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "d310955106c358c8e1ea682defd8e21af44a6cba"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.12.35"
            },
            {
              "fixed": "6.12.109"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "6.15.4"
            },
            {
              "fixed": "6.16"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.109"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.50"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.16.0"
            },
            {
              "fixed": "7.2.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93224.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Fix unmatched rn_unregister on failed accept\n\nWhen svc_rdma_accept() takes the errout path before\nrpcrdma_rn_register() has succeeded, the existing cleanup block\ncalls rpcrdma_rn_unregister(dev, \u0026newxprt-\u003esc_rn) unconditionally.\nsvcxprt_rdma is kzalloc'd, so on that path sc_rn.rn_index is 0 and\nsc_rn.rn_done is NULL; the unregister therefore xa_erase()s another\ncaller's slot 0 and performs an unmatched kref_put() on the\nrpcrdma_device's rd_kref.\n\nThe same errout also brackets the cleanup with svc_xprt_get()/\nsvc_xprt_put() around the kref_init() birth reference. The kref\ngoes 1 -\u003e 2 -\u003e 1 and never reaches 0, so the svcxprt_rdma (and the\nnet/ns_tracker it pinned) is leaked on every failed accept.\n\nrpcrdma_rn_register() writes rn-\u003ern_done last, only after xa_alloc()\nand kref_get() have both succeeded, so rn_done == NULL is a natural\n\"never registered\" sentinel. Guard rpcrdma_rn_unregister() with an\nearly return when rn_done is NULL, and clear rn_done before the\nmatching xa_erase() so a repeated unregister is also a no-op.\n\nWith that guard in place, the accept errout drops the kref_init()\nbirth reference via svc_xprt_put(), which dispatches svc_rdma_free().\nTeardown of sc_qp, sc_sq_cq, sc_rq_cq, and sc_pd runs under existing\nIS_ERR/NULL guards in svc_rdma_free(); sc_rn is covered by the new\nrn_done sentinel; sc_cm_id is non-NULL on every errout path because\nsvc_rdma_accept() dereferences it above the first goto errout.\n\nsvc_xprt_free() drops the module reference associated with the freed\ntransport, and svc_handle_xprt() drops its pre-acquired reference\nwhen -\u003expo_accept() returns NULL. Take a replacement module reference\nbefore svc_xprt_put() so the two module_put()s remain balanced.\n\nThe rn_done guard also covers svc_rdma_free()'s non-listener call\nto rpcrdma_rn_unregister() for transports whose register attempt\nfailed or never ran.",
  "id": "CVE-2026-93224",
  "modified": "2026-09-26T03:30:58.068893466Z",
  "published": "2026-09-24T15:21:10.542Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0335800071a6dfdf7d21d729b5e7d8fa98936211"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/26190394c64c9429481fc88a4738f70bb92fb352"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/45a444a17240f4fa2235f0dfd4a96fc80f1eb2c2"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5aabe070c00e5bdf4ab150fb5f72ad5f266d6241"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93224.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93224"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "svcrdma: Fix unmatched rn_unregister on failed accept"
}