Unchecked Return Value in Linux kernel - CVE-2026-89547
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt kernel memory.
The vulnerability exists due to unchecked return values in the SUNRPC RPC service pool counter initialization in __svc_create() when starting an RPC service while per-CPU counter allocation fails. A local privileged user can start an RPC service under allocation failure conditions to corrupt kernel memory.
Exploitation requires memory pressure or fault injection during RPC server startup; a remote peer cannot induce the failed allocation state on its own.