CVE-2026-89536
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: wait for in-flight client TLS handshake callback
xstlshandshakesync() gives xstlshandshakedone() a reference to the
lower transport before submitting the handshake request. On timeout or
signal, the synchronous waiter drops that reference after calling
tlshandshakecancel().
handshakereqcancel() returns false when handshake_complete() has
already marked the request complete. In that case the completion callback
can still be running, so dropping the callback-owned reference in the
waiter can free the lower transport before xstlshandshake_done() stores
xprt_err or drops its own reference.
If cancellation loses to completion, wait until xstlshandshake_done()
signals handshake_done and let the callback release its reference. This
mirrors the server-side handshake lifetime handling and keeps the timeout
or signal return value unchanged.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/15431820f448e09f8029b670d5c82aa5917d4625, https://git.kernel.org/stable/c/1de391e8b94e31b45c19c16dbf315e294810c7de, https://git.kernel.org/stable/c/7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b, https://git.kernel.org/stable/c/a89dd597458848b463d284b15e42a8078beeb046, https://git.kernel.org/stable/c/fb43997407bc17ee39bac81ab708101312e255f5, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89536.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89536, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git