Executive brief
The Linux kernel's RDMA (Remote Direct Memory Access) subsystem manages resources used for high-speed network data transfers. A race condition in the Protection Domain deallocation function allowed systems to access freed memory briefly via the netlink interface, potentially causing system crashes or data corruption. This affects systems using RDMA networking, including high-performance computing clusters and enterprise data centers.
Technical details
A use-after-free vulnerability exists in the ib_dealloc_pd_user() function within drivers/infiniband/core/verbs.c. The vulnerability arises because rdma_restrack_del() was called after vendor-specific resources were freed, creating a window where the Protection Domain (PD) remained accessible through the restrack API while its internal structures were already deallocated. An attacker with network access to the netlink interface could trigger concurrent access to the freed PD via rdma_restrack_get(). The fix moves rdma_restrack_begin_del() to the start of the deallocation process, ensuring the PD is removed from the resource tracking list before any internal resources are released. A corresponding rdma_restrack_abort_del() call was added to handle error paths properly.
Affected products
- Linux Linux Kernel Affected versions across multiple kernel series (2.6.11 through 7.2)
Timeline
- 2026-09-17: disclosed: CVE-2026-92507 published
- 2026-07-13: patched: Fix committed upstream by Patrisious Haddad (commit 8b90e701342275f414e36e7421c502237df241ad)