Skip to main content

In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove… (CVE-2026-89510)

0
Medium
Published: 09/11/2026 (09/11/2026, 21:31:30 UTC)
Source: GCVE Database

Description

A use-after-free vulnerability in the Linux kernel's RDMA cxgb4 driver was resolved by ensuring that pending registration work is canceled before the device is freed during removal. The flaw involved the c4iw_uld_state_change() function queuing registration work that could access a device after it was freed by c4iw_remove(), potentially causing invalid memory access.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 01:10:52 UTC

Technical Analysis

The vulnerability in the Linux kernel RDMA cxgb4 driver arises because c4iw_uld_state_change() queues reg_work to register the RDMA device, but c4iw_remove() can free the device context while this work is still pending or executing. This leads to c4iw_register_device() accessing a freed device, causing a use-after-free condition. The fix involves canceling the reg_work before device removal to prevent access to freed memory. The registration work can also tear down the device context if registration fails, so the fix avoids double unregistering or deallocating the device. This issue was identified via an in-house static analysis tool.

Potential Impact

The vulnerability could lead to use-after-free conditions in the kernel, potentially causing system instability or crashes. No known exploits are reported in the wild. The impact is limited to systems using the affected RDMA cxgb4 driver in the Linux kernel.

Mitigation Recommendations

A fix is available that cancels the pending registration work before freeing the device during removal, preventing use-after-free access. Users should apply the official Linux kernel update that includes this fix. No additional mitigation steps are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-82cq-j2q5-4p5v
Osv Schema Version
1.4.0
Aliases
["CVE-2026-89510"]

Threat ID: 6aa4a01555bf5e2cf5a866da

Added to database: 09/12/2026, 00:43:01 UTC

Last enriched: 09/12/2026, 01:10:52 UTC

Last updated: 09/12/2026, 01:10:52 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses