Executive brief
A flaw in the Linux kernel's RDMA (Remote Direct Memory Access) core subsystem allows a completion queue (CQ)—a critical component of InfiniBand networking—to remain accessible after its internal resources have been freed. An attacker with network access to an RDMA-enabled system could trigger this race condition to read or corrupt memory, potentially compromising data confidentiality or causing system crashes.
Technical details
This is a use-after-free vulnerability in the RDMA core's ib_destroy_cq_user() function (drivers/infiniband/core/verbs.c). The root cause is an ordering issue in resource lifecycle management: the function previously called rdma_restrack_del() at the end of destruction, after vendor-specific CQ resources had already been freed. This created a window where the CQ remained accessible via the netlink restrack interface, but its underlying memory had been deallocated. An attacker with network access could query the CQ via netlink during this window, leading to use-after-free. The fix moves rdma_restrack_begin_del() to the start of destruction, ensuring the CQ is unregistered from restrack before any resources are released. The vulnerability affects all Linux kernel versions with RDMA resource tracking support. A patch is available in the stable kernel tree (commit 3481bec4dfc4aee24ffea5a547ee95b70b67d9d5).
Affected products
- Linux Linux kernel all versions with RDMA resource tracking (introduced by commit 08f294a1524b, patched in commit 3481bec4dfc4aee24ffea5a547ee95b70b67d9d5)
Timeline
- 2026-09-17: disclosed: CVE published and advisory released
- 2026-07-13: patched: Fix committed to upstream kernel (commit 3481bec4dfc4aee24ffea5a547ee95b70b67d9d5) and backported to stable branches