{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90308","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.800Z","datePublished":"2026-09-17T16:08:29.704Z","dateUpdated":"2026-09-18T17:54:27.165Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:27.165Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Hold QP references for AE and CM processing\n\nAE QP fatal events and iWARP CM paths load QPs from dev->qp_xa\nand then use or reference them outside the xarray lock.\nerdma_destroy_qp() can drop the destroy-path reference and free QP\nresources while such a lookup is in flight.\n\nAdd erdma_qp_get_by_qpn() to acquire a kref under the xarray\nlock with kref_get_unless_zero(). Remove the QP from the xarray\nbefore dropping the destroy-path reference so no new lookup can acquire\nit while destruction waits for existing users."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is a race between local ib_uverbs_destroy_qp()->erdma_destroy_qp() dropping the QP kref and either ucma_connect()/ucma_accept() (RDMA_USER_CM_CONNECT/ACCEPT -> iw_cm_connect()/iw_cm_accept() -> erdma_connect()/erdma_accept() xa_load of userspace params->qpn) or erdma_comm_irq_handler()->erdma_aeq_event_handler(). The CM QPN is rdma_ucm_conn_param.qp_num, not a remote iWARP/RoCE field.\nAC:L - The attacker who created the QP drives both sides: one thread issues ucma_connect()/ucma_accept() or QP ops that produce an AEQE, while another calls ib_uverbs_destroy_qp(), racing find_qp_by_qpn()/xa_load against the destroy-path erdma_qp_put(). The window (bare xa_load, then kref_get or no get at all) can be retried across many QPs.\nPR:L - ib_uverbs_open() and ucma_open() perform no capability check; uverbs_devnode() and ucma_misc.mode publish /dev/infiniband/uverbs* and /dev/infiniband/rdma_cm as 0666, so an unprivileged user on an ERDMA host can create_qp, RDMA_USER_CM_CONNECT/ACCEPT, and destroy_qp.\nUI:N - The attacker creates the QP via uverbs, issues ucma_connect()/ucma_accept() (or generates an AEQE) and ib_uverbs_destroy_qp() from their own processes; no other user must mount, open, or otherwise act.\nS:U - The use-after-free is of the host kernel's struct erdma_qp (kref, ibqp.event_handler, queue buffers) under the same kernel authority and does not cross a VM, IOMMU, or guest-host boundary.\nC:H - After erdma_destroy_qp() drops the last kref and the RDMA core frees the QP, erdma_aeq_event_handler() still reads qp->ibqp.event_handler and qp_context from the freed object, and erdma_connect() may kref_get a freed QP; a sprayed replacement yields a kernel-memory read primitive.\nI:H - erdma_aeq_event_handler() invokes qp->ibqp.event_handler on the freed erdma_qp, and erdma_connect()/erdma_accept() write qp->cep and take qp->state_lock after a lockless xa_load; reclaiming that object gives a function-pointer call and kernel writes.\nA:H - Using the QP after erdma_qp_put()/wait_for_completion() has released its queues and the ib_qp object causes a kernel oops or panic in erdma_aeq_event_handler() or in erdma_connect()/erdma_accept()."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_cm.c","drivers/infiniband/hw/erdma/erdma_eq.c","drivers/infiniband/hw/erdma/erdma_verbs.c","drivers/infiniband/hw/erdma/erdma_verbs.h"],"versions":[{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"6e32f84b63c054e09392153125d7202abab2d14b","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"ec987c0654651036dad6a42f7fa2a6d7c16a3687","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"c92686867638cda954fdb2bdbac8a75e3aa6eaae","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"a52eeff32024f190b3bdc99088c7becccd4fa60b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_cm.c","drivers/infiniband/hw/erdma/erdma_eq.c","drivers/infiniband/hw/erdma/erdma_verbs.c","drivers/infiniband/hw/erdma/erdma_verbs.h"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6e32f84b63c054e09392153125d7202abab2d14b"},{"url":"https://git.kernel.org/stable/c/ec987c0654651036dad6a42f7fa2a6d7c16a3687"},{"url":"https://git.kernel.org/stable/c/c92686867638cda954fdb2bdbac8a75e3aa6eaae"},{"url":"https://git.kernel.org/stable/c/a52eeff32024f190b3bdc99088c7becccd4fa60b"}],"title":"RDMA/erdma: Hold QP references for AE and CM processing","x_generator":{"engine":"bippy-1.2.0"}}}}