PT-2026-72781 · Linux · Linux Kernel
CVE-2026-74345
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the RDMA/siw component regarding endpoint and socket association handling. Disassociating a socket from an endpoint using the
siw socket disassoc() function may release the last reference to that endpoint, leading to it being freed. This can result in a slab-use-after-free (a situation where the system attempts to access memory after it has been marked as free) within the siw cm work handler() function. This condition can be triggered during connection establishment when processing a malformed MPA request, which causes the new endpoint to be closed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel