Junglewise Threat Intelligence

CVE-2026-45910: Linux Kernel RDMA/rxe race condition in QP timer handlers

CVE-2026-45910 · Severity: info · CVSS 4.7 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. This flaw could potentially lead to a system crash or unpredictable behavior when network queue pairs are destroyed while a retransmission timer is simultaneously firing. While primarily affecting system stability, it represents a technical debt in how the kernel manages memory references during high-speed networking operations.

Technical details

A race condition exists between the retransmit_timer() and rnr_nak_timer() handlers and the rxe_destroy_qp function in the RDMA/rxe driver. The vulnerability occurs when a Queue Pair's (QP) reference count drops to zero during the execution of a timer handler, leading to a refcount_t underflow and potential use-after-free (UAF) scenario. An attacker with local access could potentially trigger this race to cause a kernel panic (DoS). The fix involves ensuring the QP's reference count is incremented using rxe_get(qp) at the start of the timer callback and decremented with rxe_put(qp) after use, while also verifying the QP's validity within the protected spinlock section.

Affected products

  • Linux Linux Kernel 6.19.0-rc5-64k-v8+; fixed in various stable branches

Timeline

  • 2026-01-20: other: Patch submitted by Li Zhijian
  • 2026-03-04: patched: Committed to stable branches
  • 2026-05-27: advisory: CVE-2026-45910 published

References

Related threats