{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92508","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.872Z","datePublished":"2026-09-17T16:10:19.443Z","dateUpdated":"2026-09-18T17:55:32.156Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:32.156Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix potential use after free in ib_free_cq()\n\nWhen accessing a CQ via the netlink path the only synchronization\nmechanism for the said CQ is rdma_restrack_get().\nCurrently, rdma_restrack_del() is invoked at the end of\nib_free_cq(), which is too late, since by that point\nvendor-specific resources associated with the CQ might already be\nfreed. This can leave a short window where the CQ remains accessible\nthrough restrack, leading to a potential use-after-free.\n\nFix this by moving the rdma_restrack_del() call to be before the freeing\nof the vendor-specific resources ensuring that the CQ is removed from\nrestrack before its internal resources are released.\nThis guarantees that no new users hold references to a CQ that is in\nthe process of destruction."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The use side is a local NETLINK_RDMA RDMA_NLDEV_CMD_RES_CQ_GET handled by nldev_res_get_cq_doit/dumpit → res_get_common_doit/dumpit, which rdma_restrack_get()s a CQ still in the xarray while ib_free_cq() is destroying it. No remote protocol message carries the lookup; the accessor is a netlink syscall.\nAC:L - The attacker drives both sides of the race: one thread loops RDMA_NLDEV_CMD_RES_CQ_GET while another opens and drops kernel-ULP RDMA connections so ib_free_cq() runs (svc_rdma_free() or smbdirect_connection_destroy_qp()). That is not a victim-only timing window.\nPR:L - RDMA_NLDEV_CMD_RES_CQ_GET in nldev_cb_table has no RDMA_NL_ADMIN_PERM, and NETLINK_RDMA is created with NL_CFG_F_NONROOT_RECV, so an ordinary user can dump CQs. Kernel CQ teardown via /dev/infiniband/rdma_cm (ucma_misc mode 0666) also does not need init-namespace root.\nUI:N - The attacker sends the RDMA_NLDEV_CMD_RES_CQ_GET dumps and tears down their own kernel-ULP RDMA connections; no other user must mount a volume, open a device, or confirm an action.\nS:U - The UAF is of host-kernel CQ vendor state (ib_cq buffers freed in destroy_cq/pre_destroy_cq) and stays inside the same kernel authority; it is not a VM escape, IOMMU bypass, or guest-to-host boundary cross.\nC:H - c4iw_destroy_cq() → destroy_cq() dma_free_coherent()s chp->cq.queue before rdma_restrack_del(); a concurrent fill_res_cq_entry → c4iw_fill_res_cq_entry still indexes that queue, so the UAF reads freed CQ-ring memory.\nI:H - The same ib_free_cq() window lets fill_res_cq_entry use vendor CQ resources already released by destroy_cq/pre_destroy_cq (Chelsio queue pages; mlx5 destroy_cq_kernel CQ buffers). Reclaiming that heap object yields an arbitrary write and control-flow hijack.\nA:H - fill_res_cq_entry walking a CQ whose queue or HW context was already freed in ib_free_cq() (after pre_destroy_cq/destroy_cq, before rdma_restrack_del) oopses or panics the kernel even without a crafted exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/cq.c"],"versions":[{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"a804b162f9bc2b38b2ed1b4752eea9faadb1645b","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"91f8a17a22ab615a03743120e19935e731f28fb9","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"76f2cb4f721815c3b6262a6dc2151de88646924c","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"b8dcca427096fc9c50f1b376847fea72bc842d31","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"9abea37942534eeb049335476178696b654b000c","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"43403fe45379c64fa6276e5a8ede44493e5d2d3d","status":"affected","versionType":"git"},{"version":"43d781b9fa562f0c6e50f62c870fbfeb9dc85213","lessThan":"29dc2f8e1c97372c2871a70088707933515fbd5b","status":"affected","versionType":"git"},{"version":"7ac277a01f9017fcde4f3f81670c995992945433","status":"affected","versionType":"git"},{"version":"093f87dda065e0f618dd577985eccbe85efb9b54","status":"affected","versionType":"git"},{"version":"5.8.17","lessThan":"5.9","status":"affected","versionType":"semver"},{"version":"5.9.2","lessThan":"5.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/cq.c"],"versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a804b162f9bc2b38b2ed1b4752eea9faadb1645b"},{"url":"https://git.kernel.org/stable/c/91f8a17a22ab615a03743120e19935e731f28fb9"},{"url":"https://git.kernel.org/stable/c/76f2cb4f721815c3b6262a6dc2151de88646924c"},{"url":"https://git.kernel.org/stable/c/b8dcca427096fc9c50f1b376847fea72bc842d31"},{"url":"https://git.kernel.org/stable/c/9abea37942534eeb049335476178696b654b000c"},{"url":"https://git.kernel.org/stable/c/43403fe45379c64fa6276e5a8ede44493e5d2d3d"},{"url":"https://git.kernel.org/stable/c/29dc2f8e1c97372c2871a70088707933515fbd5b"}],"title":"RDMA/core: Fix potential use after free in ib_free_cq()","x_generator":{"engine":"bippy-1.2.0"}}}}