Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Fix use-after-free in siw_accept()

siw_accept() looks up the QP supplied by userspace. If that QP is
already in RTS, the function jumps to error cleanup before associating
the incoming CEP with it.

The cleanup tests whether qp->cep is non-NULL and assumes the current
call installed the association. However, qp->cep can point to the CEP
of an existing connection. The cleanup then drops a reference from the
incoming cep, not qp->cep. Once the incoming endpoint loses its
remaining references, this can free it before the subsequent cep->qp
store, causing a use-after-free. It also clears the existing QP
association.

Only release the association reference when qp->cep is the incoming
CEP. This preserves an existing association and avoids accessing the
freed endpoint.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption in the RDMA/siw subsystem caused by a‑after‑free
Action: Patch immediately
AI Analysis

Impact

The bug arises in the RDMA/siw accept routine when a queue pair that is already in the Ready‑To‑Send state is processed. During error cleanup the code mistakenly drops a reference from the incoming Connection Endpoint rather than the existing QP’s endpoint, which can free that endpoint before it is reused. This sequence can trigger a use‑after‑free that corrupts kernel memory and clears an existing queue‑pair association.

Affected Systems

All Linux kernel releases that include the original siw_accept() implementation in the RDMA/siw subsystem. No specific version range is provided, so any kernel containing this code path is at risk until a kernel update that incorporates the fix is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1 % suggests a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an untrusted or compromised userspace process that can initiate RDMA connections to the kernel, exercising the vulnerable code path.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the siw_accept() fix to eliminate the use‑after‑free.
  • If a kernel update is not immediately available, disable RDMA/siw support by blacklisting or removing the rdma_siwi driver, or block all RDMA traffic to the affected hosts with firewall or network policies.
  • Enable kernel hardening options such as KASLR, noexec, and stack protection to reduce the impact of any remaining memory corruption.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix use-after-free in siw_accept() siw_accept() looks up the QP supplied by userspace. If that QP is already in RTS, the function jumps to error cleanup before associating the incoming CEP with it. The cleanup tests whether qp->cep is non-NULL and assumes the current call installed the association. However, qp->cep can point to the CEP of an existing connection. The cleanup then drops a reference from the incoming cep, not qp->cep. Once the incoming endpoint loses its remaining references, this can free it before the subsequent cep->qp store, causing a use-after-free. It also clears the existing QP association. Only release the association reference when qp->cep is the incoming CEP. This preserves an existing association and avoids accessing the freed endpoint.
Title RDMA/siw: Fix use-after-free in siw_accept()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:21.875Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:26.400

Modified: 2026-09-18T18:17:52.147

Link: CVE-2026-90292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses