PT-2026-43951 · Linux+2 · Linux Kernel+2

CVE-2026-46084

·

Published

2026-05-27

·

Updated

2026-09-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-1.1
Description An issue exists in the RDMA mana ib component where the mana ib destroy qp rss() function destroys RX WQ objects without disabling vPort RX steering in the firmware. This results in stale steering configurations that point to destroyed RX objects. If traffic continues to arrive and the VF interface is subsequently restarted via mana open, the firmware may deliver completions using stale CQ IDs. These IDs can be reused by the ethernet driver for new TX CQs, leading to RX completions being incorrectly delivered to TX CQs, which triggers kernel warnings in mana poll tx cq() and mana gd process eq events().
Recommendations Update to version 7.0.11-1.1 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88673
CVE-2026-46084
OPENSUSE-SU-2026:10954-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3595-1
SUSE-SU-2026:3602-1
SUSE-SU-2026:3617-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu