{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  RDMA/ucma: Lock the handler in ucma_write_cm_event()  ctx-\u003efile may only be changed under the handler lock and the xa_lock, which is what stops uevents being queued for a ctx while ucma_migrate_id() moves it to another file.  The CM core takes that lock before invoking ucma_event_handler(), but the write() paths that queue uevents themselves do not.  ucma_write_cm_event() re-reads ctx-\u003efile for each of its four dereferences, so ucma_migrate_id() can swap it mid-sequence:  \tmutex_lock(\u0026ctx-\u003efile-\u003emut);\t\t\t/* file A */ \tlist_add_tail(\u0026uevent-\u003elist, \u0026ctx-\u003efile-\u003eevent_list);\t/* file B */ \tmutex_unlock(\u0026ctx-\u003efile-\u003emut);\t\t\t/* file B */ \twake_up_interruptible(\u0026ctx-\u003efile-\u003epoll_wait);\t/* file B */  The window is the mutex_lock() itself: the writer sleeps in it while the migration reassigns ctx-\u003efile.  The list_add_tail() then runs on file B's event_list holding only file A's mutex:    list_add corruption. prev-\u003enext should be next (ffff888101320f30),     but was ffff88814a08c418. (prev=ffff88814a075c18).   kernel BUG at lib/list_debug.c:32!   Call Trace:    ucma_write_cm_event+0x36e/0x5e0  and file A's mut is left held forever, wedging its next writer in D state. The uevent is also stranded on a list ucma_cleanup_ctx_events() will not walk, so it outlives its context.  /dev/infiniband/rdma_cm is 0666 and no RDMA device is involved, so an unprivileged user reaches all of this.  Take the handler lock, as ucma_cleanup_mc_events() does; ctx-\u003ecm_id is pinned by the ucma_get_ctx() reference.",
  "id": "DEBIAN-CVE-2026-89507",
  "modified": "2026-09-14T08:47:46.520132828Z",
  "published": "2026-09-11T20:19:33.027Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89507"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89507"
  ]
}