PT-2026-94520 · Linux · Linux Kernel
CVE-2026-90172
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the smbdirect component of the Linux kernel where memory pools are destroyed before the Queue Pair (QP) during an accept failure. In the
rdma accept failed error path of the smbdirect accept connect request() function, a receive I/O object remains outstanding on the QP. Because the system calls smbdirect connection destroy mem pools() before smbdirect connection destroy qp(), the memory pools and the recv io slab cache are destroyed while the object is still active. This leads to a state where objects remain during kmem cache destroy() and subsequently causes a NULL-pointer dereference in mempool free bulk when the object is finally freed into a destroyed mempool.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel