KernelScan.io

CRITICAL Introduced in 6.5

sunrpc Handshake Race

CVE-2026-89536

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.1HIGH

01

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.

02

Engine v0.6.0

Risk summary

A race condition in the NFS client's TLS handshake handling can cause use-after-free of the underlying transport when a handshake timeout or signal interrupts the wait. A malicious or compromised NFS server can trigger this by timing TLS handshake responses to coincide with the client's timeout, potentially leading to kernel memory corruption, privilege escalation, or system crash. Systems using NFS with RPC-with-TLS (RFC 9289) are affected.

Affectednet/sunrpc/xprtsock.c (SUNRPC)

Vulnerability analysis

A race condition in the NFS client's TLS handshake handling can free the underlying transport while the handshake completion callback is still running. When a TLS handshake times out or is interrupted by a signal, the cancellation may lose to a completion callback that has already started; the original code drops the transport reference regardless, potentially freeing it before the callback finishes accessing it. The fix detects when cancellation has lost to completion and waits for the callback to finish and release its own reference before returning. This is reachable when a system mounts NFS using RPC-with-TLS; a malicious or compromised NFS server can trigger the race by timing its TLS response to coincide with the client's handshake timeout.

03

BranchIntroducedFixed inPatch commit
6.186.56.18.501de391e8b94e
6.66.56.6.157fb43997407bc
6.126.56.12.10915431820f448
7.26.57.2.47fbb6d2ab039
mainline6.57.3-rc1a89dd5974588