PT-2026-94521 · Linux · Linux Kernel
CVE-2026-90173
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A slab-use-after-free issue exists in the smbdirect component of the Linux kernel. The function
smbdirect connection destroy qp() uses ib destroy cq() to tear down completion queues (CQs) created with ib alloc cq any(). However, ib destroy cq() frees the queues without cancelling the internal completion handler that runs ib cq poll work() on a workqueue. If a provider posts a completion late, the handler may re-queue ib cq poll work() on a queue that has already been freed, leading to an access fault in rxe req notify cq().Recommendations
Replace the use of
ib destroy cq() with ib free cq() to ensure that poll work is synchronized and cancelled before the completion queue is freed.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel