PT-2026-43719 · Linux+3 · Linux Kernel+3

CVE-2026-45852

·

Published

2026-01-12

·

Updated

2026-08-23

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A double free issue exists in the RDMA/rxe component. In the rxe srq from init() function, the queue pointer q is assigned to srq->rq.queue before the SRQ number is copied to user space. If the copy to user() function fails, rxe queue cleanup() is called to free the queue, but an invalid pointer remains in srq->rq.queue. Subsequently, the caller function rxe create srq() triggers rxe srq cleanup(), which results in a second call to rxe queue cleanup() on the same memory address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Multiple Releases of Same Resource or Handle

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25120
ALSA-2026:25121
ALSA-2026:25217
BDU:2026-11748
CVE-2026-45852
OESA-2026-2673
OESA-2026-2674
OPENSUSE-SU-2026:20965-1
RHSA-2026:25120
RHSA-2026:25121
RHSA-2026:25217
RHSA-2026:27713
RHSA-2026:33899
RHSA-2026:34094
RHSA-2026:35863
RHSA-2026:35896
RHSA-2026:41236
SUSE-SU-2026:22099-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:2310-1
SUSE-SU-2026:2331-1
SUSE-SU-2026:2332-1
SUSE-SU-2026:2383-1
SUSE-SU-2026:2421-1
SUSE-SU-2026:2450-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu