Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana_ib: drain QP references after partial table insertion

mana_table_store_ud_qp() publishes a QP at its send-queue id before
inserting the receive-queue id, dropping the XArray lock between the two
xa_insert_irq() calls. A concurrent completion handler can look up the QP
and take a transient reference. When the second insertion fails, the
rollback erased only the send-queue entry and returned, leaving both the
initial table reference and the transient reference outstanding while RDMA
core frees the QP, causing a use-after-free.

Drain the reference as normal destruction does: drop the initial reference
and wait for qp->free, releasing the QP only after every concurrent lookup
returns its reference.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in the RDMA/mana_ib subsystem could allow kernel privilege escalation or denial of service
Action: Patch ASAP
AI Analysis

Impact

The kernel bug in mana_table_store_ud_qp publishes a QP reference before fully inserting the receive queue entry and releases the XArray lock between the two xa_insert_irq calls. A completion handler running concurrently can acquire a transient reference to the QP while the second insertion fails and only rolls back the first entry. This leaves both the initial table reference and the transient reference outstanding. When RDMA core later frees the QP, the stale references trigger a use‑after‑free, permitting an attacker to execute code in kernel mode or crash the system. The flaw is a classic use‑after‑free condition (CWE‑416) and carries the potential for arbitrary code execution or denial of service.

Affected Systems

All Linux kernel builds that include the RDMA/mana_ib driver before the patch that removes the race between the two xa_insert_irq calls are affected. The vulnerability does not involve a specific kernel version in the data provided, so any kernel that has not yet incorporated the referenced commit is at risk.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low exploitation probability in the wild. However, the flaw grants kernel‑level persistence and the affectation of RDMA core implies a high CVSS severity potential. Attack vectors would involve initiating RDMA operations that trigger the partial insertion race, which requires local access to RDMA resources but may be feasible for privileged users or within compromised workloads. Because the issue requires concurrent operation, exploitation might be harder to achieve, aligning with the low EPSS score, but it remains a high‑risk flaw due to the privilege level it can compromise.

Generated by OpenCVE AI on September 19, 2026 at 06:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the fix for mana_table_store_ud_qp; the patch removes the race condition that leads to the use‑after‑free.
  • If RDMA functionality is not required, disable the RDMA/mana_ib driver by removing the corresponding module or setting the kernel configuration option to exclude RDMA support.
  • Restrict access to RDMA device files so that only trusted users or processes can perform RDMA operations; consider using SELinux or AppArmor profiles to limit RDMA exposure.

Generated by OpenCVE AI on September 19, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() publishes a QP at its send-queue id before inserting the receive-queue id, dropping the XArray lock between the two xa_insert_irq() calls. A concurrent completion handler can look up the QP and take a transient reference. When the second insertion fails, the rollback erased only the send-queue entry and returned, leaving both the initial table reference and the transient reference outstanding while RDMA core frees the QP, causing a use-after-free. Drain the reference as normal destruction does: drop the initial reference and wait for qp->free, releasing the QP only after every concurrent lookup returns its reference.
Title RDMA/mana_ib: drain QP references after partial table insertion
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:22.793Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92513

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.140

Modified: 2026-09-17T17:17:54.140

Link: CVE-2026-92513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:00:08Z

Weaknesses