Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Hold CQ references when processing EQ events

EQ handlers look up CQs from dev->cq_xa and invoke CQ completion or
error callbacks outside the xarray lock. erdma_destroy_cq() can erase the
CQ from the xarray and free its queue buffer and doorbell record while a
previously scheduled EQ handler is still using the CQ.

Add a CQ refcount and take a reference under the xarray lock with
refcount_inc_not_zero(). Remove the CQ from the xarray before dropping
the destroy-path reference, then wait for in-flight EQ users before
releasing CQ resources.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to arbitrary code execution
Action: Apply kernel patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s RDMA/erdma subsystem where an EQ handler may invoke callbacks on a Completion Queue that has already been destroyed and freed. The CQ is removed from the xarray and its resources released while an EQ handler still holds a reference to it, creating a classic use‑after‑free scenario. If an attacker can trigger RMDA events that cause the handler to run during or after the free, kernel memory can be corrupted or arbitrary code can be executed with kernel privileges.

Affected Systems

All Linux kernel builds that include the RDMA/erdma driver, and that have not yet applied the fix, are potentially affected. No specific version range is given in the data, so the impact applies broadly to any kernel that ships the unpatched driver code.

Risk and Exploitability

The CVSS score of 7.8 classifies flaw as high severity, while the EPSS score of less than 1% indicates a low probability of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so no widespread confirmed exploitation has been reported. Based on the description, the likely attack vector is local, requiring that an adversary can trigger RDMA events or otherwise interact with the RDMA driver on the affected system. There is no clear public-facing network exploitation path reported.

Generated by OpenCVE AI on September 20, 2026 at 03:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that contains the RDMA/erdma CQ reference counting fix
  • Reboot the system to load the new kernel and ensure the patched driver is active
  • If an immediate kernel update cannot be performed, temporarily disable RDMA modules or devices until the patch is applied

Generated by OpenCVE AI on September 20, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-404

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold CQ references when processing EQ events EQ handlers look up CQs from dev->cq_xa and invoke CQ completion or error callbacks outside the xarray lock. erdma_destroy_cq() can erase the CQ from the xarray and free its queue buffer and doorbell record while a previously scheduled EQ handler is still using the CQ. Add a CQ refcount and take a reference under the xarray lock with refcount_inc_not_zero(). Remove the CQ from the xarray before dropping the destroy-path reference, then wait for in-flight EQ users before releasing CQ resources.
Title RDMA/erdma: Hold CQ references when processing EQ events
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:28.510Z

Reserved: 2026-09-11T19:38:34.800Z

Link: CVE-2026-90309

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.637

Modified: 2026-09-18T18:17:52.977

Link: CVE-2026-90309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:15:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-404

    Improper Resource Shutdown or Release