{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46112","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.098Z","datePublished":"2026-05-28T09:35:20.879Z","dateUpdated":"2026-08-05T12:29:44.058Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:29:44.058Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix unlocked call to hns_roce_qp_remove()\n\nSashiko points out that hns_roce_qp_remove() requires the caller to hold\nlocks.  The error flow in hns_roce_create_qp_common() doesn't hold those\nlocks for the error unwind so it risks corrupting memory.\n\nGrab the same locks the other two callers use."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the local RDMA uverbs character device (ibv_create_qp), a control-plane operation; it cannot be triggered by a remote peer sending RDMA packets.\nAC:L - The attacker can reliably force the error-unwind path (e.g., a faulting ib_copy_to_udata output buffer) and controls both sides of the race by running concurrent QP create/destroy and CQ-poll operations on the same device/CQs.\nPR:L - Creating a QP requires access to the RDMA verbs device but no CAP/root; an unprivileged local user with RDMA access (common in HPC/cloud/container deployments) can reach the code.\nUI:N - The attacker triggers QP creation and the error path directly with no action required from any other user.\nS:U - Corruption stays within the kernel's own memory/security authority; no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - Unlocked list_del causes linked-list corruption that can be leveraged into use-after-free and arbitrary kernel-memory disclosure; per guidance memory corruption exploitable for info leak is High.\nI:H - Racing list_del/list_add writes attacker-influenced pointer values into neighbor nodes, a memory-corruption write primitive that can be escalated to control-flow hijack; High.\nA:H - List corruption and the resulting use-after-free reliably oops/panic the kernel, a full denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/hns/hns_roce_qp.c"],"versions":[{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"1f0a3aa8b569d010316b427238222c5d899f9618","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"b6296ff2475fc95ee6ea1b528c4b385302808186","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"fb4ae739811d467409bd07d0e36cfd4140f3d26a","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"fcf6a832c0d5b2bc5398d6996c5570d3ee7993fb","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"1912f78798505dc9c637081bbddfbf1c22494c49","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"615d9d260c32bb678504ca96f29ae46f9d745155","status":"affected","versionType":"git"},{"version":"e088a685eae94a0607b8f7b99949a0e14d748813","lessThan":"0c99acbc8b6c6dd526ae475a48ee1897b61072fb","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/hns/hns_roce_qp.c"],"versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.88","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.12.88"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"6.18.30"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.0.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.17","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1f0a3aa8b569d010316b427238222c5d899f9618"},{"url":"https://git.kernel.org/stable/c/b6296ff2475fc95ee6ea1b528c4b385302808186"},{"url":"https://git.kernel.org/stable/c/fb4ae739811d467409bd07d0e36cfd4140f3d26a"},{"url":"https://git.kernel.org/stable/c/fcf6a832c0d5b2bc5398d6996c5570d3ee7993fb"},{"url":"https://git.kernel.org/stable/c/1912f78798505dc9c637081bbddfbf1c22494c49"},{"url":"https://git.kernel.org/stable/c/615d9d260c32bb678504ca96f29ae46f9d745155"},{"url":"https://git.kernel.org/stable/c/0c99acbc8b6c6dd526ae475a48ee1897b61072fb"}],"title":"RDMA/hns: Fix unlocked call to hns_roce_qp_remove()","x_generator":{"engine":"bippy-1.2.0"}}}}