PT-2026-94520 · Linux · Linux Kernel

CVE-2026-90172

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the smbdirect component of the Linux kernel where memory pools are destroyed before the Queue Pair (QP) during an accept failure. In the rdma accept failed error path of the smbdirect accept connect request() function, a receive I/O object remains outstanding on the QP. Because the system calls smbdirect connection destroy mem pools() before smbdirect connection destroy qp(), the memory pools and the recv io slab cache are destroyed while the object is still active. This leads to a state where objects remain during kmem cache destroy() and subsequently causes a NULL-pointer dereference in mempool free bulk when the object is finally freed into a destroyed mempool.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90172
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel