Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Add refcounting to user ring MRs

Prevent userspace from deregistering the MRs that back QP/CQ/SRQ rings
by bumping the MR's refcount upon association.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

A flaw in the RDMA/irdma subsystem of the Linux kernel allowed a userspace process to deregister memory regions that were still referenced by kernel RDMA rings, potentially causing the kernel to free memory in use and later access it again. Such an error can lead to a kernel crash, disrupting service availability. The patch that added refcounting prevents this race condition.

Affected Systems

All Linux kernel builds that include the irdma driver and have not applied commit 07974c267f603a76aead348bca97deee95efdcc9 are potentially affected. No specific kernel versions are listed, so any distribution shipping an unpatched kernel with irdma support is at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates that, at present, organized exploitation appears unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need local access to a process interacting with RDMA devices to trigger the race, which is considered an inference based on the information available. The patch removes the risk by enforcing a reference count on memory regions that back RDMA rings.

Generated by OpenCVE AI on September 19, 2026 at 15:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a revision that includes the irdma refcounting patch (commit 07974c267f603a76aead348bca97deee95efdcc9).
  • If a kernel update cannot be performed immediately, unload or disable the irdma module to prevent RDMA operations from using the vulnerable code.
  • Reboot the host after applying the patch or disabling the module to ensure the new kernel image and RDMA state are fully reset.

Generated by OpenCVE AI on September 19, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Add refcounting to user ring MRs Prevent userspace from deregistering the MRs that back QP/CQ/SRQ rings by bumping the MR's refcount upon association.
Title RDMA/irdma: Add refcounting to user ring MRs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:16.837Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93154

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.710

Modified: 2026-09-18T18:18:23.060

Link: CVE-2026-93154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:13Z

Weaknesses