{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90423","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.814Z","datePublished":"2026-09-17T16:09:46.513Z","dateUpdated":"2026-09-18T17:55:18.624Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:18.624Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix UAF in ODP init error-handling path\n\nrxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before\ncalling rxe_odp_init_pages(). If rxe_odp_init_pages() fails,\nrxe_odp_mr_init_user() releases umem_odp and returns an error.\n\nrxe_reg_user_mr() then unwinds the error through rxe_cleanup(),\nrxe_mr_cleanup(), ib_umem_release(mr->umem). There is an\nIS_ERR_OR_NULL(umem) check at the start of ib_umem_release().\nBut since mr->umem is NOT reset to NULL in the error handling\npath of rxe_odp_mr_init_user(), the check passes and it reads\nalready-freed fields like umem->is_dmabuf, causing UAF.\n\nFix the UAF by clearing mr->umem after releasing the failed\nODP umem so the MR cleanup path does not release it again."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled bytes are cmd.access_flags (IB_ACCESS_ON_DEMAND), cmd.start and cmd.length from IB_USER_VERBS_CMD_REG_MR written to /dev/infiniband/uverbsN; ib_uverbs_write→ib_uverbs_reg_mr→rxe_reg_user_mr→rxe_odp_mr_init_user. Soft-RoCE packet receive never supplies that REG_MR command.\nAC:L - rxe_odp_init_pages() fails when ib_umem_odp_map_dma_and_lock() returns an error from hmm_range_fault(); a second thread in the same process can munmap the REG_MR VA so rxe_ib_invalidate_range() keeps invalidating the mmu_interval until HMM_RANGE_DEFAULT_TIMEOUT (1000ms) expires with -EBUSY. The UAF on that error path is then deterministic.\nPR:L - uverbs_devnode() publishes /dev/infiniband/uverbs* as 0666; ib_uverbs_open, ib_uverbs_get_context, ib_uverbs_alloc_pd and ib_uverbs_reg_mr have no capability checks, and rxe_init_device_param sets IBK_ON_DEMAND_PAGING so ib_check_mr_access() accepts IB_ACCESS_ON_DEMAND.\nUI:N - The attacker opens uverbs, allocates a PD, and issues REG_MR with IB_ACCESS_ON_DEMAND against a VA range they own; no other user must mount, open, or confirm anything.\nS:U - rxe_mr_cleanup() calls ib_umem_release() on the dangling mr->umem inside the same host kernel; this does not cross a KVM, Xen, or IOMMU boundary.\nC:H - After ib_umem_odp_release() kfree's umem_odp, ib_umem_release(mr->umem) reads the freed umem->is_dmabuf and umem->is_odp; slab reuse lets the attacker control those flags and later pointers such as ibdev and owning_mm.\nI:H - The dangling mr->umem still has is_odp set, so ib_umem_release() calls ib_umem_odp_release() again and kfree's the already-freed umem_odp, a heap double-free write primitive.\nA:H - The UAF load of umem->is_dmabuf in ib_umem_release() and the second free of umem_odp oops or KASAN-crash the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_odp.c"],"versions":[{"version":"d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91","lessThan":"5f1933163327c9f1c8f2a341c6cb551aaf231ff9","status":"affected","versionType":"git"},{"version":"d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91","lessThan":"4cfb448705da3171d44d9cbe7be53ff03284d532","status":"affected","versionType":"git"},{"version":"d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91","lessThan":"51f2c8d2c99fc1f452f7113c08a35edcc4bf8732","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_odp.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5f1933163327c9f1c8f2a341c6cb551aaf231ff9"},{"url":"https://git.kernel.org/stable/c/4cfb448705da3171d44d9cbe7be53ff03284d532"},{"url":"https://git.kernel.org/stable/c/51f2c8d2c99fc1f452f7113c08a35edcc4bf8732"}],"title":"RDMA/rxe: Fix UAF in ODP init error-handling path","x_generator":{"engine":"bippy-1.2.0"}}}}