Executive brief
A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) over Ethernet driver. A specific error handling failure during the creation of shared receive queues could allow a local attacker to trigger a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and availability in environments utilizing RDMA technology.
Technical details
A double-free vulnerability exists in the RDMA/rxe driver within the rxe_srq_from_init() function. The vulnerability is caused by assigning a queue pointer to 'srq->rq.queue' before a call to copy_to_user(). If copy_to_user() fails, the function calls rxe_queue_cleanup() to free the queue but does not nullify the pointer in 'srq->rq.queue'. Subsequently, the caller (rxe_create_srq) calls rxe_srq_cleanup() upon receiving the error, which triggers a second rxe_queue_cleanup() on the same memory address. This can be exploited by a local user to cause a kernel panic or memory corruption. The fix involves reordering the assignment to occur only after a successful copy_to_user() operation.
Affected products
- Linux Linux kernel RDMA/rxe component
Timeline
- 2026-05-27: advisory: NVD publication date
- 2026-01-15: patched: Initial fix committed to mainline kernel
References
- https://git.kernel.org/stable/c/0beefd0e15d962f497aad750b2d5e9c3570b66d1
- https://git.kernel.org/stable/c/22b8c23a3b92d023614bb00896fe364b2c1a31d3
- https://git.kernel.org/stable/c/26793db60925df1e88a29466813d586cbc190b8c
- https://git.kernel.org/stable/c/26a9cfe12f4ffdeaa136f252478986fa5f397ddc
- https://git.kernel.org/stable/c/5c07aef09a121a4cd622a71eb0753a9e135c84a8
- https://git.kernel.org/stable/c/af5956243018918130d52c9f671efdb40bab3366
- https://git.kernel.org/stable/c/ce6f8e007682f378279d4cf83b240f12d52c723b