Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Fix CEQ tasklet use-after-free on removal

Each CEQ interrupt handler only schedules eqc->tasklet. The tasklet calls
erdma_ceq_completion_handler(), which reads the DMA-coherent EQ ring
through get_next_valid_eqe() and updates eq->dbrec through notify_eq().

erdma_ceqs_uninit() frees each CEQ IRQ and then destroys its EQ.
free_irq() prevents another hard IRQ and waits for an in-flight handler,
but it does not drain a tasklet that the handler already scheduled. The
tasklet can therefore access eq->qbuf or eq->dbrec after
erdma_eq_destroy() frees them.

Clearing ceq_cb->ready does not synchronize with a tasklet that already
passed the check at the start of erdma_ceq_completion_handler().

Kill the tasklet after free_irq(), when no handler can schedule it again,
and before erdma_ceq_uninit_one() releases the EQ buffers.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in the erdma tasklet may cause a kernel crash
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs when the erdma CEQ interrupt handler schedules a tasklet that later accesses DMA‑coherent memory that has been freed during CEQ removal. This use‑after‑free leads to a memory corruption in the kernel, potentially triggering a panic or crash. The weakness is a classic memory‑corruption flaw, consistently classified as CWE‑416.

Affected Systems

The flaw attacks the Linux kernel RDMA/erdma driver. Any system that loads the erdma module and runs a kernel version before the referenced commit fixes is susceptible. No specific release dates are provided, so all current kernels that have not yet incorporated the patch are at risk.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability (<1 %), and the vulnerability is not listed in the CISA KEV catalog. A CVSS score has not been disclosed. Exploitation requires initiating a CEQ removal, which typically demands privileged kernel access; this requirement is inferred from the nature of the operation but is not explicitly stated in the advisory.

Generated by OpenCVE AI on September 19, 2026 at 13:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that incorporates the erdma CEQ tasklet fix, such as the commit series referenced in the advisory.
  • If a kernel upgrade cannot be performed immediately, prevent removal of CEQs or unloading of the erdma module until the patch is applied; ensure no pending tasklets are scheduled.
  • Apply the individual commit patches (e.g., 0ca7997, 0e8b78d, 61a25b8, 6e129c1, a60c36d, f738c0a) to the working kernel or a custom build until an official distribution package becomes available.

Generated by OpenCVE AI on September 19, 2026 at 13:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removal Each CEQ interrupt handler only schedules eqc->tasklet. The tasklet calls erdma_ceq_completion_handler(), which reads the DMA-coherent EQ ring through get_next_valid_eqe() and updates eq->dbrec through notify_eq(). erdma_ceqs_uninit() frees each CEQ IRQ and then destroys its EQ. free_irq() prevents another hard IRQ and waits for an in-flight handler, but it does not drain a tasklet that the handler already scheduled. The tasklet can therefore access eq->qbuf or eq->dbrec after erdma_eq_destroy() frees them. Clearing ceq_cb->ready does not synchronize with a tasklet that already passed the check at the start of erdma_ceq_completion_handler(). Kill the tasklet after free_irq(), when no handler can schedule it again, and before erdma_ceq_uninit_one() releases the EQ buffers.
Title RDMA/erdma: Fix CEQ tasklet use-after-free on removal
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:23.462Z

Reserved: 2026-09-16T12:21:13.873Z

Link: CVE-2026-92514

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:54.243

Modified: 2026-09-17T17:17:54.243

Link: CVE-2026-92514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:15:16Z

Weaknesses