Junglewise Threat Intelligence

CVE-2026-92508: Linux kernel RDMA/core use-after-free in ib_free_cq()

CVE-2026-92508 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA (Remote Direct Memory Access) subsystem has a race condition in the completion queue (CQ) deallocation function. When an application frees a CQ, a small window exists where the CQ remains accessible through the netlink interface even though internal resources have already been freed. An attacker with network access to the RDMA stack could exploit this to trigger a crash or potentially execute code, affecting systems using RDMA-based storage or high-performance networking.

Technical details

The vulnerability is a use-after-free (CWE-416) in the ib_free_cq() function within drivers/infiniband/core/cq.c. The root cause is a race condition where rdma_restrack_del() was called too late in the deallocation sequence—after vendor-specific resources were already freed. This left a window where external callers accessing the CQ via the netlink/restrack path could obtain references to a CQ with deallocated internal resources. The fix moves rdma_restrack_del() earlier in the teardown sequence, before device-specific destroy operations, ensuring the CQ is unregistered from the tracking interface before any resources are released. The vulnerability affects any kernel version with the RDMA subsystem; a local or network-adjacent attacker with access to RDMA netlink operations could trigger the race condition. Patches are available in upstream and stable kernel trees.

Affected products

  • Linux Linux kernel All versions with RDMA/core subsystem (approximately 2.6.11 onwards)

Timeline

  • 2026-09-17: disclosed: CVE-2026-92508 published
  • 2026-07-22: patched: Fix committed upstream (commit 29dc2f8e1c97372c2871a70088707933515fbd5b)
  • 2026-09-14: patched: Fix backported to stable kernel trees

References

Related threats