In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject connection when transport allocation fails handle_connect_req()… (CVE-2026-89531)
A vulnerability in the Linux kernel's svcrdma component was resolved that caused connection requests to be improperly handled when transport allocation failed. Specifically, the function handle_connect_req() returned without action when svc_rdma_create_xprt() failed to allocate a new transport, leading to a resource leak of rdma_cm_id objects under memory pressure. This leak could be amplified by a remote peer repeatedly attempting connections. The fix involves rejecting the connection by returning a non-zero status from the connection manager event handler, prompting proper cleanup of the orphaned rdma_cm_id.
AI Analysis
Technical Summary
The Linux kernel svcrdma module had a flaw where handle_connect_req() did not reject connection requests when svc_rdma_create_xprt() failed to allocate a transport. The connection manager (CM) core returned 0 for CONNECT_REQUEST events, preventing destruction of the new rdma_cm_id and causing a resource leak. Under memory pressure, this leak could be exploited by a remote peer to amplify resource consumption. The vulnerability was fixed by modifying the CM event handler to return a non-zero status on allocation failure, ensuring the CM core destroys the orphaned rdma_cm_id and prevents leaks.
Potential Impact
The vulnerability causes a resource leak of rdma_cm_id objects in the Linux kernel under memory pressure conditions. A remote attacker can amplify this by repeatedly initiating connection attempts, potentially leading to denial of service due to resource exhaustion. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented that causes the connection manager event handler to reject connection requests when transport allocation fails, ensuring proper cleanup of resources. Users should apply the official Linux kernel update that includes this fix. Since no vendor advisory or patch link is provided, check the official Linux kernel repositories or vendor advisories for the patch and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject connection when transport allocation fails handle_connect_req()… (CVE-2026-89531)
Description
A vulnerability in the Linux kernel's svcrdma component was resolved that caused connection requests to be improperly handled when transport allocation failed. Specifically, the function handle_connect_req() returned without action when svc_rdma_create_xprt() failed to allocate a new transport, leading to a resource leak of rdma_cm_id objects under memory pressure. This leak could be amplified by a remote peer repeatedly attempting connections. The fix involves rejecting the connection by returning a non-zero status from the connection manager event handler, prompting proper cleanup of the orphaned rdma_cm_id.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel svcrdma module had a flaw where handle_connect_req() did not reject connection requests when svc_rdma_create_xprt() failed to allocate a transport. The connection manager (CM) core returned 0 for CONNECT_REQUEST events, preventing destruction of the new rdma_cm_id and causing a resource leak. Under memory pressure, this leak could be exploited by a remote peer to amplify resource consumption. The vulnerability was fixed by modifying the CM event handler to return a non-zero status on allocation failure, ensuring the CM core destroys the orphaned rdma_cm_id and prevents leaks.
Potential Impact
The vulnerability causes a resource leak of rdma_cm_id objects in the Linux kernel under memory pressure conditions. A remote attacker can amplify this by repeatedly initiating connection attempts, potentially leading to denial of service due to resource exhaustion. There is no indication of code execution or privilege escalation from the provided data.
Mitigation Recommendations
A fix has been implemented that causes the connection manager event handler to reject connection requests when transport allocation fails, ensuring proper cleanup of resources. Users should apply the official Linux kernel update that includes this fix. Since no vendor advisory or patch link is provided, check the official Linux kernel repositories or vendor advisories for the patch and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vgrv-wfr9-vqh2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89531"]
Threat ID: 6aa4a01455bf5e2cf5a866ce
Added to database: 09/12/2026, 00:43:00 UTC
Last enriched: 09/12/2026, 01:09:44 UTC
Last updated: 09/12/2026, 01:09:44 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.