Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix potential use after free in ib_destroy_srq_user()

When accessing a SRQ via the netlink path the only synchronization
mechanism for the said SRQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_destroy_srq_user(), which is too late, since by that point
vendor-specific resources associated with the SRQ might already be
freed. This can leave a short window where the SRQ remains accessible
through restrack, leading to a potential use-after-free.

Fix this by moving the rdma_restrack_begin_del() call to the start of
ib_destroy_srq_user(), ensuring that the SRQ is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a SRQ that is in the process of destruction.

In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to kernel memory corruption
Action: Apply patch
AI Analysis

Impact

The bug occurs when a Shared Receive Queue (SRQ) is destroyed in the RDMA core driver. The destruction routine invokes a clean‑up function too late, after vendor‑specific resources have already been freed, leaving the SRQ still referenced by the restrack mechanism. An attacker that can initiate a netlink request to access an SRQ may use the remaining reference to trigger a use‑after‑free, potentially corrupting kernel memory or causing a crash. The underlying weakness is a classic use‑after‑free error (CWE‑416).

Affected Systems

The vulnerability applies to all Linux kernel builds that contain the unpatched ib_destroy_srq_user function. The impacted vendors are represented by the Linux upstream kernel project. No specific version range was supplied, so any kernel that shipped before the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high severity issue. The EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is currently not listed in the CISA KEV catalog. The attack requires administrative or kernel‑space privileges to send a netlink command that references a user‑mode SRQ (inferred), making the exploitation path limited to privileged users or compromised applications with RDMA access. Nonetheless, the combination of a use‑after‑free and privileged netlink access (inferred) gives an attacker the potential to corrupt memory or crash the kernel, which could be leveraged for privilege escalation or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 22:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s kernel update that contains the patched ib_destroy_srq_user implementation
  • If updating is not immediately possible, limit netlink access to RDMA commands by applying stricter SELinux or AppArmor policies
  • Avoid using the RDMA subsystem from untrusted or low‑privilege processes until the kernel is patched

Generated by OpenCVE AI on September 19, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_srq_user() When accessing a SRQ via the netlink path the only synchronization mechanism for the said SRQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_destroy_srq_user(), which is too late, since by that point vendor-specific resources associated with the SRQ might already be freed. This can leave a short window where the SRQ remains accessible through restrack, leading to a potential use-after-free. Fix this by moving the rdma_restrack_begin_del() call to the start of ib_destroy_srq_user(), ensuring that the SRQ is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a SRQ that is in the process of destruction. In addition, this change preserves the intended inverted order between create and destroy routines: resources are added to restrack at the end of successful creation, and hence shall be removed from the restrack first thing during the destruction flow, which keeps the lifecycle management consistent and predictable.
Title RDMA/core: Fix potential use after free in ib_destroy_srq_user()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:33.514Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92510

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:53.720

Modified: 2026-09-18T18:18:13.660

Link: CVE-2026-92510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses