Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix potential use after free in ib_free_cq()

When accessing a CQ via the netlink path the only synchronization
mechanism for the said CQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_free_cq(), which is too late, since by that point
vendor-specific resources associated with the CQ might already be
freed. This can leave a short window where the CQ remains accessible
through restrack, leading to a potential use-after-free.

Fix this by moving the rdma_restrack_del() call to be before the freeing
of the vendor-specific resources ensuring that the CQ is removed from
restrack before its internal resources are released.
This guarantees that no new users hold references to a CQ that is in
the process of destruction.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in the RDMA core that can lead to kernel crashes
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel a use‑after‑free flaw exists in the RDMA core during the freeing of completion queues (CQ). When a CQ is destroyed through the netlink interface, the rdma_restrack_del() function is called too late, after vendor‑specific resources may already have been released. This creates a brief window where the CQ remains reachable via the restrack mechanism, allowing an attacker to use freed memory and potentially trigger kernel crashes.

Affected Systems

All Linux kernel installations that incorporate the RDMA core subsystem and expose the RDMA netlink interface are affected. The vulnerability is present in any kernel where the ib_free_cq() routine is used to deallocate CQs, as the issue originates from the timing of the rdma_restrack_del() call relative to vendor resource cleanup.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the EPSS score of less than 1% shows a very low yet non‑zero probability of exploitation. The vulnerability is not yet listed in the CISA KEV catalog, suggesting the exploitation activity is not broadly observed. The likely attack vector is a local privileged attacker with access to the RDMA netlink interface; remote exploitation would require additional compromises. Given the low EPSS and absence from KEV, the overall risk, while significant if exploited, is considered moderate compared to the high severity score.

Generated by OpenCVE AI on September 19, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the ib_free_cq use‑after‑free fix, such as patch sets following commit 29dc2f8e1c97372c2871a70088707933515fbd5b
  • Rebuild or reload any RDMA‑related modules with the updated kernel headers, ensuring that rdma_restrack_del() executes before vendor resources are freed
  • If an immediate kernel upgrade cannot be applied, restrict access to the RDMA netlink interface or disable it entirely for non‑privileged users to prevent dangling references during CQ destruction

Generated by OpenCVE AI on September 19, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_free_cq(), which is too late, since by that point vendor-specific resources associated with the CQ might already be freed. This can leave a short window where the CQ remains accessible through restrack, leading to a potential use-after-free. Fix this by moving the rdma_restrack_del() call to be before the freeing of the vendor-specific resources ensuring that the CQ is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a CQ that is in the process of destruction.
Title RDMA/core: Fix potential use after free in ib_free_cq()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:32.156Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:53.433

Modified: 2026-09-18T18:18:13.500

Link: CVE-2026-92508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses