{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90309","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.800Z","datePublished":"2026-09-17T16:08:30.346Z","dateUpdated":"2026-09-18T17:54:28.510Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:28.510Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Hold CQ references when processing EQ events\n\nEQ handlers look up CQs from dev->cq_xa and invoke CQ completion or\nerror callbacks outside the xarray lock. erdma_destroy_cq() can erase the\nCQ from the xarray and free its queue buffer and doorbell record while a\npreviously scheduled EQ handler is still using the CQ.\n\nAdd a CQ refcount and take a reference under the xarray lock with\nrefcount_inc_not_zero(). Remove the CQ from the xarray before dropping\nthe destroy-path reference, then wait for in-flight EQ users before\nreleasing CQ resources."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached by IB_USER_VERBS_CMD_DESTROY_CQ/UVERBS_METHOD_CQ_DESTROY on /dev/infiniband/uverbsN racing erdma_ceq_completion_handler and erdma_aeq_event_handler; CEQE/AEQE CQNs are written by the ERDMA NIC for locally created CQs, not parsed from a remote RoCE/iWARP message.\nAC:L - The attacker drives both sides: userspace SQ/RQ doorbells via erdma_mmap (or ib_uverbs_post_send) make the NIC post CEQEs and schedule the CEQ tasklet, while another thread runs ib_uverbs_destroy_cq; pre-fix erdma_destroy_cq xa_erase'd the CQ with no ref wait, so the race is attacker-controlled.\nPR:L - ib_uverbs_open allows CQ create/destroy with no capability check; uverbs_devnode sets /dev/infiniband/uverbsN to mode 0666, and erdma_alloc_ucontext/erdma_create_cq/erdma_destroy_cq do not require CAP_NET_ADMIN or init-namespace root.\nUI:N - The attacker creates the CQ via ib_uverbs_create_cq, generates EQ events from their own QPs, and tears it down via ib_uverbs_destroy_cq/uverbs_free_cq on that uverbs fd; no other user must mount, open a file, or otherwise act.\nS:U - The dangling erdma_cq is used inside the same host kernel that issued the uverbs destroy (comp_handler/event_handler on ibcq); this is in-kernel privilege escalation, not a KVM/Xen guest-to-host or IOMMU/DMA boundary bypass.\nC:H - After ib_destroy_cq_user kfree(cq), erdma_ceq_completion_handler still reads cq->ibcq.comp_handler and cq->ibcq.cq_context from the freed object, and ib_uverbs_comp_handler then follows cq->uobject, giving a UAF read of kernel heap.\nI:H - The same dangling pointer is used to invoke cq->ibcq.comp_handler (and on AEQ CQ_ERR, cq->ibcq.event_handler); kernel CQs also do cq->kern_cq.cmdsn++. Calling a function pointer from a freed erdma_cq is an arbitrary-write/control-flow hijack primitive.\nA:H - erdma_ceq_completion_handler or erdma_aeq_event_handler dereferencing the kfree'd erdma_cq (junk comp_handler/uobject) oopses the kernel, and repeating create_cq/destroy_cq while CEQ/AEQ events are in flight panics the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_eq.c","drivers/infiniband/hw/erdma/erdma_verbs.c","drivers/infiniband/hw/erdma/erdma_verbs.h"],"versions":[{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"610ef81797bb4f709e8675c1d8d093bb9ccdcbd8","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"c0a83f29a24c7e7f8516630848ef6db4c174deed","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"05b8ca493dd02319bca93c640b259c2ba51ef321","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"1fc9c1933959d2776a1ce7bf424251b8b5b586cd","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"4545f355654d044d35a31cd01cc46f491a8a7c36","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"98df2aee1459ee1c62c70cbe9b370d2a532aea36","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_eq.c","drivers/infiniband/hw/erdma/erdma_verbs.c","drivers/infiniband/hw/erdma/erdma_verbs.h"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/610ef81797bb4f709e8675c1d8d093bb9ccdcbd8"},{"url":"https://git.kernel.org/stable/c/c0a83f29a24c7e7f8516630848ef6db4c174deed"},{"url":"https://git.kernel.org/stable/c/05b8ca493dd02319bca93c640b259c2ba51ef321"},{"url":"https://git.kernel.org/stable/c/1fc9c1933959d2776a1ce7bf424251b8b5b586cd"},{"url":"https://git.kernel.org/stable/c/4545f355654d044d35a31cd01cc46f491a8a7c36"},{"url":"https://git.kernel.org/stable/c/98df2aee1459ee1c62c70cbe9b370d2a532aea36"}],"title":"RDMA/erdma: Hold CQ references when processing EQ events","x_generator":{"engine":"bippy-1.2.0"}}}}