Executive brief
A race condition was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. This flaw could potentially lead to a system crash or unpredictable behavior when network queue pairs are destroyed while a retransmission timer is simultaneously firing. While primarily affecting system stability, it represents a technical debt in how the kernel manages memory references during high-speed networking operations.
Technical details
A race condition exists between the retransmit_timer() and rnr_nak_timer() handlers and the rxe_destroy_qp function in the RDMA/rxe driver. The vulnerability occurs when a Queue Pair's (QP) reference count drops to zero during the execution of a timer handler, leading to a refcount_t underflow and potential use-after-free (UAF) scenario. An attacker with local access could potentially trigger this race to cause a kernel panic (DoS). The fix involves ensuring the QP's reference count is incremented using rxe_get(qp) at the start of the timer callback and decremented with rxe_put(qp) after use, while also verifying the QP's validity within the protected spinlock section.
Affected products
- Linux Linux Kernel 6.19.0-rc5-64k-v8+; fixed in various stable branches
Timeline
- 2026-01-20: other: Patch submitted by Li Zhijian
- 2026-03-04: patched: Committed to stable branches
- 2026-05-27: advisory: CVE-2026-45910 published
References
- https://git.kernel.org/stable/c/3c2ae79fb19dfd67341c14f1e78a5f1744eacfe2
- https://git.kernel.org/stable/c/5ae9da022ee3c97e6469eabcddce9271501ddbad
- https://git.kernel.org/stable/c/756c93d6df7c3bc599f6590b8e5afead6a41de1c
- https://git.kernel.org/stable/c/87bf646921430e303176edc4eb07c30160361b73
- https://git.kernel.org/stable/c/da379ca16af3722f159860d91a99cb6976a7500f