Junglewise Threat Intelligence

CVE-2026-45852: Linux Kernel double free in RDMA/rxe rxe_srq_from_init

CVE-2026-45852 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) over Ethernet driver. A specific error handling failure during the creation of shared receive queues could allow a local attacker to trigger a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and availability in environments utilizing RDMA technology.

Technical details

A double-free vulnerability exists in the RDMA/rxe driver within the rxe_srq_from_init() function. The vulnerability is caused by assigning a queue pointer to 'srq->rq.queue' before a call to copy_to_user(). If copy_to_user() fails, the function calls rxe_queue_cleanup() to free the queue but does not nullify the pointer in 'srq->rq.queue'. Subsequently, the caller (rxe_create_srq) calls rxe_srq_cleanup() upon receiving the error, which triggers a second rxe_queue_cleanup() on the same memory address. This can be exploited by a local user to cause a kernel panic or memory corruption. The fix involves reordering the assignment to occur only after a successful copy_to_user() operation.

Affected products

  • Linux Linux kernel RDMA/rxe component

Timeline

  • 2026-05-27: advisory: NVD publication date
  • 2026-01-15: patched: Initial fix committed to mainline kernel

References

Related threats