CRITICAL Introduced in 6.5
sunrpc Handshake Race
CVE-2026-89536
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.
02KernelScan AI Analysis
Risk summary
A race condition in the NFS client's TLS handshake handling can cause use-after-free of the underlying transport when a handshake timeout or signal interrupts the wait. A malicious or compromised NFS server can trigger this by timing TLS handshake responses to coincide with the client's timeout, potentially leading to kernel memory corruption, privilege escalation, or system crash. Systems using NFS with RPC-with-TLS (RFC 9289) are affected.
Vulnerability analysis
A race condition in the NFS client's TLS handshake handling can free the underlying transport while the handshake completion callback is still running. When a TLS handshake times out or is interrupted by a signal, the cancellation may lose to a completion callback that has already started; the original code drops the transport reference regardless, potentially freeing it before the callback finishes accessing it. The fix detects when cancellation has lost to completion and waits for the callback to finish and release its own reference before returning. This is reachable when a system mounts NFS using RPC-with-TLS; a malicious or compromised NFS server can trigger the race by timing its TLS response to coincide with the client's handshake timeout.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 6.5 | 6.18.50 | 1de391e8b94e |
| 6.6 | 6.5 | 6.6.157 | fb43997407bc |
| 6.12 | 6.5 | 6.12.109 | 15431820f448 |
| 7.2 | 6.5 | 7.2.4 | 7fbb6d2ab039 |
| mainline | 6.5 | 7.3-rc1 | a89dd5974588 |