Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/rvt: Return NULL after port allocation failure

rvt_alloc_device() deallocates the IB device when its port array cannot
be allocated but then returns the pointer to the released allocation.
Callers treat any non-NULL value as valid and dereference it, resulting
in a use-after-free.

Return NULL immediately after deallocation so callers can propagate the
allocation failure.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free leading to memory corruption and potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

During RDMA rvt device allocation, when the port array cannot be allocated, the function frees the allocated device but returns the pointer to the released memory. Callers treat any non-NULL value as a valid device pointer, causing a use-after-free that can corrupt memory, crash the system, or provide arbitrary code execution if an attacker can influence the deallocation path. The bug is contained in the Linux kernel’s RDMA rvt subsystem.

Affected Systems

The flaw affects the Linux kernel’s RDMA rvt subsystem. All kernel releases that include the unpatched rvt_alloc_device() implementation are vulnerable until a patch is applied; the vendor has not published a specific version range in the advisory.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Because the issue is a classic use‑after‑free, the impact is severe. Based on the description, it is inferred that an attacker would need to trigger the allocation failure path, likely requiring local or higher privileges to reach the vulnerable code.

Generated by OpenCVE AI on September 19, 2026 at 09:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that removes the faulty return value in rvt_alloc_device()
  • If an immediate kernel upgrade is not possible, disable the RDMA/rvt subsystem or unload its modules until the patch is applied
  • Ensure RDMA interfaces are not exposed to untrusted users or processes by adjusting kernel parameters or network exposure

Generated by OpenCVE AI on September 19, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/rvt: Return NULL after port allocation failure rvt_alloc_device() deallocates the IB device when its port array cannot be allocated but then returns the pointer to the released allocation. Callers treat any non-NULL value as valid and dereference it, resulting in a use-after-free. Return NULL immediately after deallocation so callers can propagate the allocation failure.
Title RDMA/rvt: Return NULL after port allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:15.760Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93104

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:04.740

Modified: 2026-09-17T17:18:04.740

Link: CVE-2026-93104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses