PT-2026-94519 · Linux · Linux Kernel
CVE-2026-90171
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the smbdirect component where
smbdirect socket destroy() releases pending or ready child sockets while still holding the listener's handler lock (&id priv->handler mutex) and before the listener's own rdma destroy id() is called. This sequence can lead to a slab-use-after-free during listener shutdown because smbdirect socket release() may destroy a child's cm id before the listener's destroy id() executes cma cancel listens(), causing the latter to access freed memory. Additionally, this behavior can trigger recursive locking warnings in lockdep, as releasing a child recurses into smbdirect socket destroy(), which attempts to acquire the child's own rdma lock handler() lock while the listener's lock is still held.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel