PT-2026-94521 · Linux · Linux Kernel

CVE-2026-90173

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-use-after-free issue exists in the smbdirect component of the Linux kernel. The function smbdirect connection destroy qp() uses ib destroy cq() to tear down completion queues (CQs) created with ib alloc cq any(). However, ib destroy cq() frees the queues without cancelling the internal completion handler that runs ib cq poll work() on a workqueue. If a provider posts a completion late, the handler may re-queue ib cq poll work() on a queue that has already been freed, leading to an access fault in rxe req notify cq().
Recommendations Replace the use of ib destroy cq() with ib free cq() to ensure that poll work is synchronized and cancelled before the completion queue is freed.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90173
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel