Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Hold QP references for AE and CM processing

AE QP fatal events and iWARP CM paths load QPs from dev->qp_xa
and then use or reference them outside the xarray lock.
erdma_destroy_qp() can drop the destroy-path reference and free QP
resources while such a lookup is in flight.

Add erdma_qp_get_by_qpn() to acquire a kref under the xarray
lock with kref_get_unless_zero(). Remove the QP from the xarray
before dropping the destroy-path reference so no new lookup can acquire
it while destruction waits for existing users.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free leading to potential memory corruption or denial of service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel RDMA/erdma subsystem contains a race condition that allows a process to remove a Queue Pair (QP) while another part of the code still holds a reference to it. The likely attack vector involves an attacker sending specially crafted RDMA operations to trigger simultaneous removal and lookup of a QP. During an AE QP fatal event or an iWARP Connection Manager path, the subsystem looks up QPs from a table outside the protection of the xarray lock; if erdma_destroy_qp() frees the QP concurrently, a use-after-free can occur. Based on the description, the flaw is only exploitable when a QP is destroyed concurrently with an AE event or CM path. This flaw could let an attacker manipulating RDMA operations trigger a crash or potentially corrupt memory, compromising the integrity of the kernel.

Affected Systems

The vulnerability affects the Linux kernel, specifically the RDMA/erdma component. No specific kernel versions are listed, implying that all versions vulnerable to the original bug are at risk until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate to high severity, but the EPSS score of less than 1% suggests that the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or network-based adversary with the ability to issue RDMA/erDMA commands on the affected system. Exploitation would require an attacker to manipulate the QP lifecycle during AE events or CM paths, allowing a use-after-free that could lead to a denial of service or memory corruption.

Generated by OpenCVE AI on September 20, 2026 at 00:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the RDMA/erdma fix
  • If an upgrade cannot be performed immediately, disable the RDMA/erDMA driver or restrict RDMA device access to trusted users
  • Verify that the erdma subsystem is not inadvertently loaded on hosts that do not require RDMA functionality
  • Monitor kernel logs for signs of QP fatal events or abnormal crash activity

Generated by OpenCVE AI on September 20, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold QP references for AE and CM processing AE QP fatal events and iWARP CM paths load QPs from dev->qp_xa and then use or reference them outside the xarray lock. erdma_destroy_qp() can drop the destroy-path reference and free QP resources while such a lookup is in flight. Add erdma_qp_get_by_qpn() to acquire a kref under the xarray lock with kref_get_unless_zero(). Remove the QP from the xarray before dropping the destroy-path reference so no new lookup can acquire it while destruction waits for existing users.
Title RDMA/erdma: Hold QP references for AE and CM processing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:27.165Z

Reserved: 2026-09-11T19:38:34.800Z

Link: CVE-2026-90308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.520

Modified: 2026-09-18T18:17:52.833

Link: CVE-2026-90308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses