Junglewise Threat Intelligence

CVE-2026-64033: Linux Kernel RDMA use-after-free in rtrs-srv-sysfs cleanup

CVE-2026-64033 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. This issue occurs during the cleanup process when a specific internal path fails to initialize correctly, potentially leading to a system crash or memory corruption. While primarily a technical stability issue, it could theoretically be used to disrupt operations on systems utilizing high-performance networking storage.

Technical details

A use-after-free vulnerability exists in the RDMA Trustworthy Remote Storage (RTRS) server component of the Linux kernel, specifically within the 'rtrs_srv_create_path_files' function in 'drivers/infiniband/ulp/rtrs/rtrs-srv-sysfs.c'. The root cause is an incorrect cleanup sequence in the error path: 'kobject_put()' is called before 'rtrs_srv_destroy_once_sysfs_root_folders()'. If 'kobject_put()' drops the final reference, it triggers 'rtrs_srv_release()', which frees the 'srv_path' structure. The subsequent call then attempts to dereference this freed memory. This is a local vulnerability that could lead to kernel instability or local privilege escalation. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.15.61 to 5.15.209; 6.x versions prior to various stable releases

Timeline

  • 2026-05-14: other: Vulnerability identified and patch submitted by researcher
  • 2026-06-01: patched: Patch committed to stable kernel trees
  • 2026-07-19: advisory: CVE published and NVD record created

References

Related threats