PT-2026-94818 · Linux · Linux Kernel

CVE-2026-92510

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the RDMA core component. When accessing a Shared Receive Queue (SRQ) via the netlink path, the synchronization relies on rdma restrack get(). Because rdma restrack del() was previously called at the end of the ib destroy srq user() function, vendor-specific resources associated with the SRQ could be freed while the SRQ remained accessible through restrack, creating a window for exploitation.
Recommendations As a temporary mitigation, restrict access to the ib destroy srq user() function or the RDMA core netlink path until the system is updated to a version where rdma restrack begin del() is called at the start of the destruction flow.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102812
CVE-2026-92510
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel