PT-2026-94818 · Linux · Linux Kernel
CVE-2026-92510
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the RDMA core component. When accessing a Shared Receive Queue (SRQ) via the netlink path, the synchronization relies on
rdma restrack get(). Because rdma restrack del() was previously called at the end of the ib destroy srq user() function, vendor-specific resources associated with the SRQ could be freed while the SRQ remained accessible through restrack, creating a window for exploitation.Recommendations
As a temporary mitigation, restrict access to the
ib destroy srq user() function or the RDMA core netlink path until the system is updated to a version where rdma restrack begin del() is called at the start of the destruction flow.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel