CVE-2026-89510
Last modified
CVE-2026-89510 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove c4iw_uld_state_change() queues reg_work to register the RDMA device. c4iw_remove() can free ctx->dev while this work is pending or running, leaving c4iw_register_device() accessing the freed device. Cancel reg_work before removing the device. The registration work can tear down ctx->dev when registration fails, so do not unregister or deallocate it again in that case. This issue was found by an in-house static analysis tool.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove c4iw_uld_state_change() queues reg_work to register the RDMA device. c4iw_remove() can free ctx->dev while this work is pending or running, leaving c4iw_register_device() accessing the freed device. Cancel reg_work before removing the device. The registration work can tear down ctx->dev when registration fails, so do not unregister or deallocate it again in that case. This issue was found by an in-house static analysis tool.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < e6e79e7be87c5ea92728060a3d7fb56890a91e45; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < 672ee1981db10569ec96030bddb322f18382ec04; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < 4681e731db07769846901cfabdd3e53f765eb9d3; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < 3265d558dfafab8f12f5fba06ebbf15cae9f3225; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < fe9c591026c576d8b1f72aab5e4cd67350530763; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < 85f438382a865a4dc4c50e6b884310bb2b60fc4d; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < 320e5258a53af0abc5abd9eb01519a48bab2dee8; >= 1c8f1da5d851b92aeb81dbbb9ebd516f6e2588f5, < a7100601aa1a39f799a566acce10db20eaf4b7f2 |
| Linux | Linux | 4.15 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89510?
How severe is CVE-2026-89510?
How do I fix CVE-2026-89510?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89505In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89506In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89507In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89508In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89509In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8951Spoofing issue in the Toolbar component in Firefox for Andro…6.5
- CVE-2026-89511In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-89512In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89513In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89514In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89515In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89516In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-89510?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
