PT-2026-94640 · Linux · Linux Kernel

CVE-2026-90292

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the RDMA/siw component within the siw accept() function. The function looks up a Queue Pair (QP) provided by userspace; if the QP is already in Ready to Send (RTS) state, the function triggers error cleanup before associating the incoming Connection Endpoint (CEP) with it. The cleanup process incorrectly assumes that any non-NULL qp->cep was installed by the current call, leading to the dropping of a reference from the incoming CEP instead of the existing one. This can result in the incoming endpoint being freed while still being accessed, and it also clears the existing QP association.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101888
CVE-2026-90292
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel