Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: complete object teardown when the destroy command fails

erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and
erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed,
leaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN
identifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and
permanently disables the command queue, so no retry can succeed; the RDMA
core keeps the object after a failed destructor and forced uverbs cleanup
then nulls the pointers, making the resources unreachable.

Warn on failure but release every software-owned resource and return
success, since during terminal destruction the hardware command result is
only diagnostic.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is in the Linux kernel RDMA erdma subsystem. When destroy commands for queue pairs, completion queues, memory registrations or address handles fail—typically after a command timeout—the routine returns success but does not free the software‑owned queue buffers, MTTs, doorbells, or the identifiers (STAG, QPN, CQN, AHN). This leaves those resources allocated and unreachable, causing a leak that can grow without bound and eventually exhaust system resources or the RDMA identifier pool, impairing functionality. It is inferred that the leaked resources persist until a system reboot or driver reload, as the erdma core keeps the object after a failed destructor and then sets pointers to null.

Affected Systems

All Linux kernel builds that include the erdma RDMA driver. Any system running a Linux kernel with RDMA/erdma support—such as servers, HPC nodes, or embedded platforms that compile erdma into the kernel—will be affected. The patch release notes do not provide specific version ranges, so all current releases prior to the fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.0 indicates high severity. The EPSS score is less than 1%, indicating a very low current exploitation probability. The vulnerability is not in CISA KEV. Attackers would need to invoke erdma_destroy* calls that fail; the description does not directly state the required privilege level, but based on the need to perform RDMA driver operations, it is inferred that local or privileged access is required. This inference is not proven in the description. A failure causes kernel resources to be leaked, potentially leading to exhaustion and local denial of service. There is no indication that the flaw is exploitable remotely, so remote exploitation is unlikely without additional vulnerabilities.

Generated by OpenCVE AI on September 20, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the erdma destruction bug fix.
  • Reboot the host to clear any lingering resources that may have accumulated due to the leak.
  • If RDMA functionality is not required, disable the erdma driver or block related kernel modules to mitigate the risk.

Generated by OpenCVE AI on September 20, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Sat, 19 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399
CWE-401

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destroy command fails erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed, leaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN identifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and permanently disables the command queue, so no retry can succeed; the RDMA core keeps the object after a failed destructor and forced uverbs cleanup then nulls the pointers, making the resources unreachable. Warn on failure but release every software-owned resource and return success, since during terminal destruction the hardware command result is only diagnostic.
Title RDMA/erdma: complete object teardown when the destroy command fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:26.825Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92488

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.900

Modified: 2026-09-18T18:18:12.893

Link: CVE-2026-92488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption