{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92488","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.870Z","datePublished":"2026-09-17T16:10:02.962Z","dateUpdated":"2026-09-18T17:55:26.825Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:26.825Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: complete object teardown when the destroy command fails\n\nerdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and\nerdma_destroy_ah() returned early when erdma_post_cmd_wait() failed,\nleaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN\nidentifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and\npermanently disables the command queue, so no retry can succeed; the RDMA\ncore keeps the object after a failed destructor and forced uverbs cleanup\nthen nulls the pointers, making the resources unreachable.\n\nWarn on failure but release every software-owned resource and return\nsuccess, since during terminal destruction the hardware command result is\nonly diagnostic."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached from ib_uverbs_write(IB_USER_VERBS_CMD_DESTROY_QP/DESTROY_CQ/DEREG_MR/DESTROY_AH) or ib_uverbs_ioctl(UVERBS_METHOD_*_DESTROY) on /dev/infiniband/uverbs*, which call uobj_destroy -> ib_destroy_qp_user/ib_destroy_cq_user/ib_dereg_mr_user -> erdma_destroy_*; a remote RoCE/iWARP peer never supplies that destroy command.\nAC:H - erdma_destroy_qp/cq/ah and erdma_dereg_mr only skip teardown when erdma_post_cmd_wait() fails. That wait returns -ETIME after ERDMA_CMDQ_TIMEOUT_MS and then clears ERDMA_CMDQ_STATE_OK_BIT, or -EIO on a hardware syndrome; the SQE is built by the driver from the kernel-owned QPN/CQN/lkey/AHN, so the attacker cannot force that failure.\nPR:L - ib_uverbs_open() only checks rdma_dev_access_netns() and uverbs_devnode() sets mode 0666. erdma_alloc_ucontext() requires CAP_SYS_RAWIO only when ERDMA_DEV_CAP_FLAGS_EXTEND_DB is unset; on extend-doorbell hardware an unprivileged local user can GET_CONTEXT, CREATE_QP/CQ and then hit the failing destructors.\nUI:N - The attacker issues DESTROY_* on their own uverbs fd or closes it so ib_uverbs_close() runs uverbs_destroy_ufile_hw(); no other user must mount a filesystem, open a file, or otherwise cooperate.\nS:U - A leftover erdma_cq/erdma_qp in cq_xa/qp_xa and a UAF of the associated ib_ucq_object stay inside the host kernel; this is not a KVM/Xen guest-to-host escape or an IOMMU/DMA boundary bypass.\nC:H - On command failure erdma_destroy_cq() returns before xa_erase(&dev->cq_xa). __uverbs_cleanup_ufile(RDMA_REMOVE_DRIVER_FAILURE) then nulls uobj->object without ib_destroy_cq_user and frees the ib_ucq_object, so erdma_ceq_completion_handler() -> ib_uverbs_comp_handler() reads the freed cq->uobject.\nI:H - The same ib_uverbs_comp_handler() then list_add_tail()s onto the freed ev_queue->event_list and ib_ucq_object.comp_list after DRIVER_FAILURE dropped the uobject, a use-after-free write into slab memory that can corrupt a reused object or freelist metadata.\nA:H - The CEQ tasklet UAF in ib_uverbs_comp_handler() can oops; independently, returning before erdma_free_idx()/put_mtt_entries()/dma_free_coherent() leaks STAG/QPN/CQN/AHN IDs and DMA queue buffers, and a cmdq timeout permanently disables further commands."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_verbs.c"],"versions":[{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"5fcfc988ecf3e2bbe308b95c2c0d2f011d9afabe","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"ce7d205c264665517c25e8a3231cf2d0c2443e3c","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"334145d683ad3e31d052247f10807f2ebc950351","status":"affected","versionType":"git"},{"version":"155055771704f8cbb5c176a4309b7dc30a50450c","lessThan":"652befcba956ef357f480525ccbe25c59bc81d4d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/erdma/erdma_verbs.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5fcfc988ecf3e2bbe308b95c2c0d2f011d9afabe"},{"url":"https://git.kernel.org/stable/c/ce7d205c264665517c25e8a3231cf2d0c2443e3c"},{"url":"https://git.kernel.org/stable/c/334145d683ad3e31d052247f10807f2ebc950351"},{"url":"https://git.kernel.org/stable/c/652befcba956ef357f480525ccbe25c59bc81d4d"}],"title":"RDMA/erdma: complete object teardown when the destroy command fails","x_generator":{"engine":"bippy-1.2.0"}}}}