Bug 2532155 (CVE-2026-89742) - CVE-2026-89742 kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free()
Summary: CVE-2026-89742 kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free()
Keywords:
Status: NEW
Alias: CVE-2026-89742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 21:00 UTC by OSIDB Bzimport
Modified: 2026-09-21 16:31 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 21:00:20 UTC
In the Linux kernel, the following vulnerability has been resolved:

rapidio: mport_cdev: fix use-after-free in dma_req_free()

dma_req_free() acquires buf_mutex through req->map, drops the mapping
reference with kref_put(), and then dereferences req->map again to unlock
the mutex.

If kref_put() drops the last reference, mport_release_mapping() frees the
mapping, and the subsequent mutex_unlock() dereferences a freed object. 
This is a use-after-free.

Fix this by caching map and md before kref_put(), clearing req->map while
holding buf_mutex, and using the cached md for mutex unlocking.

The bug is reachable from userspace via the RapidIO mport character device
interface.


Note You need to log in before you can comment on or make changes to this bug.