Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix potential use after free in ib_destroy_cq_user()

When accessing a CQ via the netlink path the only synchronization
mechanism for the said CQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_destroy_cq_user(), which is too late, since by that point
vendor-specific resources associated with the CQ might already be
freed. This can leave a short window where the CQ remains accessible
through restrack, leading to a potential use-after-free.

Fix this by moving the rdma_restrack_begin_del() call to the start of
ib_destroy_cq_user(), ensuring that the CQ is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a CQ that is in the process of destruction.

In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-after‑free
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s RDMA core contains a flaw in the cleanup of a completion queue (CQ). The code removes the CQ from the restrack list only after vendor‑specific resources have already been freed, creating a brief window where the CQ remains reachable through restrack while its internal memory is no longer valid, leading to a use‑after‑free. The CVE description does not specify the potential impact of the use‑after‑free beyond the possibility of accessing freed memory.

Affected Systems

The vulnerability affects all builds of the Linux kernel that lack the commit moving rdma_restrack_begin_del() to the start of ib_destroy_cq_user(). The affected vendor is Linux and the product is the Linux kernel. No explicit version range is provided, so any kernel before the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1 %, suggesting exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw is exposed when a CQ is accessed via the netlink interface, but the CVE description does not specify the required privilege level. No public exploits are known.

Generated by OpenCVE AI on September 20, 2026 at 00:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that implements the change moving rdma_restrack_begin_del() to the start of ib_destroy_cq_user().
  • If a kernel upgrade cannot be applied immediately, disable RDMA netlink access or unload the RDMA-related kernel modules until the patch is applied.
  • After applying the patch or disabling the modules, reboot the system, and monitor kernel logs (e.g., dmesg) for any remaining restrack or CQ-related errors to confirm the issue is resolved.

Generated by OpenCVE AI on September 20, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destroy_cq_user() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_destroy_cq_user(), which is too late, since by that point vendor-specific resources associated with the CQ might already be freed. This can leave a short window where the CQ remains accessible through restrack, leading to a potential use-after-free. Fix this by moving the rdma_restrack_begin_del() call to the start of ib_destroy_cq_user(), ensuring that the CQ is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a CQ that is in the process of destruction. In addition, this change preserves the intended inverted order between create and destroy routines: resources are added to restrack at the end of successful creation, and hence shall be removed from the restrack first thing during the destruction flow, which keeps the lifecycle management consistent and predictable.
Title RDMA/core: Fix potential use after free in ib_destroy_cq_user()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:34.858Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:53.850

Modified: 2026-09-18T18:18:13.837

Link: CVE-2026-92511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses