Executive brief
The Linux kernel's RDMA software iWARP (siw) driver handles remote direct memory access connections. A use-after-free vulnerability in endpoint/socket association logic allows an attacker to trigger a kernel crash or potentially execute code by sending a malformed connection request during the connection establishment phase.
Technical details
The vulnerability is a use-after-free (CWE-416) in the RDMA/siw connection management code (siw_cm.c). The root cause is that siw_socket_disassoc() may release the last reference on an endpoint structure and free it, but the calling code then attempts to clear the endpoint's socket pointer (cep->sock = NULL) after the function returns, operating on already-freed memory. The bug manifests as "KASAN: slab-use-after-free" when processing a malformed MPA (Marker PDU Aligned) request during connection establishment. The fix moves the socket pointer nullification inside siw_socket_disassoc() before the reference is released. The vulnerability requires network access to the RDMA service but does not require authentication. A remote attacker can exploit this to cause a denial-of-service (kernel panic) or potentially arbitrary code execution.
Affected products
- Linux Linux kernel linux-4.x through linux-7.x (RDMA/siw driver)
Timeline
- 2026-08-15: disclosed
- 2026-06-04: patched: Upstream fix committed as ea4f6f6c53577fb3f05dbd78b15e586772d49831
- 2026-08-15: advisory: CVE-2026-74345 published