Executive brief
A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. This issue occurs during the cleanup process when a specific internal path fails to initialize correctly, potentially leading to a system crash or memory corruption. While primarily a technical stability issue, it could theoretically be used to disrupt operations on systems utilizing high-performance networking storage.
Technical details
A use-after-free vulnerability exists in the RDMA Trustworthy Remote Storage (RTRS) server component of the Linux kernel, specifically within the 'rtrs_srv_create_path_files' function in 'drivers/infiniband/ulp/rtrs/rtrs-srv-sysfs.c'. The root cause is an incorrect cleanup sequence in the error path: 'kobject_put()' is called before 'rtrs_srv_destroy_once_sysfs_root_folders()'. If 'kobject_put()' drops the final reference, it triggers 'rtrs_srv_release()', which frees the 'srv_path' structure. The subsequent call then attempts to dereference this freed memory. This is a local vulnerability that could lead to kernel instability or local privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.15.61 to 5.15.209; 6.x versions prior to various stable releases
Timeline
- 2026-05-14: other: Vulnerability identified and patch submitted by researcher
- 2026-06-01: patched: Patch committed to stable kernel trees
- 2026-07-19: advisory: CVE published and NVD record created
References
- https://git.kernel.org/stable/c/00904a73272b9f3ef3952fe69a833909dccad1ef
- https://git.kernel.org/stable/c/01e42aabaf7632beb4bf235c7238b96c746d4144
- https://git.kernel.org/stable/c/548f3956e53a7f7bde912d8129010b8986d5e602
- https://git.kernel.org/stable/c/5b74373390113fba798a76b483837029ab010fef
- https://git.kernel.org/stable/c/92060ab1c5115674cf319175550f85f68405121f
- https://git.kernel.org/stable/c/b0e9706fb2859064bb6c677554c4d20c713aa8e0
- https://git.kernel.org/stable/c/eae62c5451e67e8b033c1681fd3b85d7e9a9a28f