Executive brief
The Linux kernel's RDMA mana driver has a race condition in the code that manages queue pairs (QPs), which are essential data structures used by InfiniBand/RDMA networking subsystems. If the second of two table insertions fails after the first succeeds, references to the queue pair object are not properly cleaned up, leading to a use-after-free condition when the kernel tries to free the object while other threads still hold references to it. This can cause a kernel crash or potential code execution.
Technical details
The vulnerability exists in the RDMA/mana_ib driver's mana_table_store_ud_qp() function. The function inserts a QP at its send-queue ID, releases the XArray lock, and then attempts to insert the receive-queue ID. During the lock gap, a concurrent completion handler can look up the QP and take a transient reference. If the second insertion fails, the rollback only erases the send-queue entry and returns without draining remaining references. This leaves both the initial table reference and the transient reference outstanding while RDMA core frees the QP, causing a use-after-free. The fix introduces a mana_table_drain_qp_ref() helper that properly drops the reference and waits for all concurrent lookups to complete before releasing the QP object.
Affected products
- Linux Linux Kernel multiple versions (patch applied upstream and backported to stable branches)
Timeline
- 2026-09-17: disclosed: CVE published
- 2026-07-21: patched: Upstream commit 97f7c2262c28ebcae64fc957ee978646684a5ed9