Executive brief
The Linux kernel's RDMA/erdma driver manages Remote Direct Memory Access event queue completion handling. A use-after-free vulnerability in the completion event queue (CEQ) removal code allows a scheduled tasklet to access freed memory buffers, potentially causing kernel crashes or memory corruption when the driver is unloaded or hardware is removed.
Technical details
The vulnerability is a use-after-free in the RDMA/erdma driver's CEQ interrupt handling and cleanup path. The CEQ interrupt handler schedules a tasklet (erdma_ceq_completion_handler) to process completion events from a DMA-coherent queue ring (eq->qbuf) and update a doorbell record (eq->dbrec). During device removal, erdma_ceqs_uninit() calls free_irq() to stop the hardware interrupt and then immediately destroys the EQ buffers. However, free_irq() only prevents new interrupt invocations and waits for in-flight handlers to complete; it does not drain tasklets that were already scheduled by the handler. The tasklet can then execute after the EQ buffers are freed, accessing eq->qbuf or eq->dbrec after they have been deallocated. The fix is to call tasklet_kill() after free_irq() but before erdma_eq_destroy() to ensure the tasklet cannot run after buffer deallocation.
Affected products
- Linux Linux kernel versions with RDMA/erdma driver (affected since introduction in earlier versions)
Timeline
- 2026-09-17: disclosed: Published in NVD
- 2026-07-22: patched: Fix committed to Linux kernel stable tree