Junglewise Threat Intelligence

CVE-2026-92510: Linux kernel RDMA use-after-free in SRQ destruction

CVE-2026-92510 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA (Remote Direct Memory Access) subsystem contains a use-after-free vulnerability in the Shared Receive Queue (SRQ) destruction function. This vulnerability allows a locally networked attacker to access SRQ resources through the netlink interface after they have been freed, potentially leading to kernel memory corruption or denial of service. Systems running vulnerable versions of the Linux kernel with RDMA support enabled are at risk.

Technical details

The vulnerability is a use-after-free (CWE-416) in the ib_destroy_srq_user() function within drivers/infiniband/core/verbs.c. The root cause is improper synchronization between resource tracking and actual resource deallocation: the rdma_restrack_del() call was placed at the end of the destroy function, after vendor-specific SRQ resources were already freed. This created a race window where netlink-based access via rdma_restrack_get() could reference already-freed vendor resources. The fix moves rdma_restrack_begin_del() to the start of the function and adds proper error handling with rdma_restrack_abort_del() on failure, ensuring the SRQ is removed from tracking before any resources are released. The attack vector requires network access and netlink interface capability but no authentication. Patches are available in Linux kernel stable branches.

Affected products

  • Linux Linux kernel Multiple versions (patch available in stable branches)

Timeline

  • 2026-09-17: disclosed
  • 2026-07-22: patched: Fix committed to mainline; backported to stable branches

References

Related threats