Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix potential use after free in counter_release()

When accessing a counter via the netlink path the only synchronization
mechanism for the said counter is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
counter_release(), which is too late, since by that point
vendor-specific resources associated with the counter might already be
freed. This can leave a short window where the counter remains
accessible through restrack, leading to a potential use-after-free.

Fix this by moving the rdma_restrack_del() call to be before the
freeing of the vendor-specific resources, ensuring that the counter is
removed from restrack before its internal resources are released.
This guarantees that no new users hold references to a counter that is
in the process of destruction.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free vulnerability
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from a short window in the Linux kernel’s RDMA core module where a counter remains registered in the restrack mechanism after its vendor‑specific resources have been freed. During this period the counter can still be accessed through the netlink interface, creating a use‑after‑free condition that could corrupt kernel memory or cause a crash. The weakness is a classic memory safety issue that directly jeopardizes kernel integrity.

Affected Systems

All Linux kernel deployments that include the RDMA core component. No specific version ranges are provided, so any kernel tree containing the affected code before the patch may be vulnerable.

Risk and Exploitability

Based on the description, the flaw arises when a counter is still accessible after its internal resources have been released, creating a use‑after‑free opportunity. The EPSS score of <1% and the absence of the vulnerability in the CISA KEV list suggest a very low probability of exploitation and no known active attacks. The likely attack vector, inferred from the use of a netlink‑based counter interface, would involve an attacker with sufficient privileges on the host to interact with the RDMA subsystem. However, the description does not confirm that remote or unprivileged access is possible, so the exact scope remains uncertain. Because the flaw is not presently exploited and requires privileged local interaction, the overall risk can be considered low until remediation is applied.

Generated by OpenCVE AI on September 19, 2026 at 13:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that relocates rdma_restrack_del() to execute before freeing vendor‑specific resources, thereby eliminating the use‑after‑free window.
  • Disable RDMA interfaces or restrict netlink counter access until the patch is in place to prevent any pre‑patch counter usage.
  • Continuously monitor kernel logs for RDMA counter errors or unexpected crashes that might indicate accidental use‑after‑free activity.

Generated by OpenCVE AI on September 19, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_release() When accessing a counter via the netlink path the only synchronization mechanism for the said counter is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of counter_release(), which is too late, since by that point vendor-specific resources associated with the counter might already be freed. This can leave a short window where the counter remains accessible through restrack, leading to a potential use-after-free. Fix this by moving the rdma_restrack_del() call to be before the freeing of the vendor-specific resources, ensuring that the counter is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a counter that is in the process of destruction.
Title RDMA/core: Fix potential use after free in counter_release()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:20.100Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:53.590

Modified: 2026-09-17T17:17:53.590

Link: CVE-2026-92509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses