Executive brief
A vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) driver could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system fails to properly manage memory during certain network hardware reconfiguration tasks. This could lead to a 'double free' condition, which compromises the stability and security of the operating system.
Technical details
A double free vulnerability exists in the RDMA/irdma driver within the Linux kernel. When the IB_MR_REREG_TRANS flag is set during a rereg_user_mr operation, the irdma_rereg_mr_trans function releases the existing umem and allocates a new one. If a subsequent step in irdma_rereg_mr_trans fails, the function releases the newly allocated umem but fails to set the iwmr->region pointer to NULL. When the failure is propagated to userspace, a subsequent call to ibv_dereg_mr triggers a second release of the same umem. This local vulnerability requires low privileges and can result in a kernel panic or memory corruption. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.6.120 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc5
Timeline
- 2026-02-27: other: Patch authored
- 2026-05-06: disclosed: Initial disclosure and NVD publication
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/0c5d70bcb9d2275a1c8515a924016fcfeb4ab441
- https://git.kernel.org/stable/c/0f22c32141acdcda266b26cab2b830baf870f3e0
- https://git.kernel.org/stable/c/29a3edd7004bb635d299fb9bc6f0ea4ef13ed5a2
- https://git.kernel.org/stable/c/62298a48f8b8788ad8b8464e6ffdf1ddebd2217e
- https://git.kernel.org/stable/c/66964118f1f50ed85001c8fc9f7ab5bbdd021ee0