{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92511","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.872Z","datePublished":"2026-09-17T16:10:21.449Z","dateUpdated":"2026-09-18T17:55:34.858Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:34.858Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix potential use after free in ib_destroy_cq_user()\n\nWhen accessing a CQ via the netlink path the only synchronization\nmechanism for the said CQ is rdma_restrack_get().\nCurrently, rdma_restrack_del() is invoked at the end of\nib_destroy_cq_user(), which is too late, since by that point\nvendor-specific resources associated with the CQ might already be\nfreed. This can leave a short window where the CQ remains accessible\nthrough restrack, leading to a potential use-after-free.\n\nFix this by moving the rdma_restrack_begin_del() call to the start of\nib_destroy_cq_user(), ensuring that the CQ is removed from restrack\nbefore its internal resources are released. This guarantees that no new\nusers hold references to a CQ that is in the process of destruction.\n\nIn addition, this change preserves the intended inverted order\nbetween create and destroy routines: resources are added to\nrestrack at the end of successful creation, and hence shall be removed\nfrom the restrack first thing during the destruction flow, which keeps\nthe lifecycle management consistent and predictable."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached by a local IB_USER_VERBS_CMD_DESTROY_CQ/UVERBS_METHOD_CQ_DESTROY on /dev/infiniband/uverbsN (ib_uverbs_destroy_cq → uobj_get_destroy → uverbs_free_cq → ib_destroy_cq_user) racing NETLINK_RDMA RDMA_NLDEV_CMD_RES_CQ_GET (nldev_res_get_cq_doit/dumpit → rdma_restrack_get_byid/rdma_restrack_get → fill_res_cq_entry). No remote RoCE/iWARP message carries the trigger.\nAC:L - The attacker drives both sides: one thread destroys their CQ via ib_uverbs_destroy_cq/uverbs_free_cq while another issues RDMA_NLDEV_CMD_RES_CQ_GET. Pre-fix, rdma_restrack_del() ran only after cq->device->ops.destroy_cq() returned, so rdma_restrack_get() still succeeds throughout vendor teardown with no victim-controlled timing.\nPR:L - ib_uverbs_open has no CAP_* check and uverbs_devnode sets /dev/infiniband/uverbsN to 0666. RDMA_NLDEV_CMD_RES_CQ_GET is registered without RDMA_NL_ADMIN_PERM, and NETLINK_RDMA unicast to portid 0 does not require CAP_NET_ADMIN, so an unprivileged user on a system with an RDMA device can create, dump, and destroy their own CQ.\nUI:N - The attacker creates the CQ with IB_USER_VERBS_CMD_CREATE_CQ/UVERBS_METHOD_CQ_CREATE, dumps it with RDMA_NLDEV_CMD_RES_CQ_GET, and destroys it with IB_USER_VERBS_CMD_DESTROY_CQ on their own uverbs fd; no other user must mount, open a file, or otherwise act.\nS:U - fill_res_cq_entry and cq->device->ops.destroy_cq run in the same host kernel that owns the ib_cq; the dangling vendor CQ state is consumed in-kernel (nldev restrack dump versus ib_destroy_cq_user), not across a KVM/Xen, IOMMU, or other authorization boundary.\nC:H - After ib_destroy_cq_user calls destroy_cq, fill_res_cq_entry still holds the CQ via rdma_restrack_get and invokes vendor fill. c4iw_destroy_cq's destroy_cq dma_free_coherent()s cq->queue and kfree()s cq->sw_queue, then c4iw_fill_res_cq_entry copies those CQEs into the netlink skb; hns_roce_fill_res_cq_entry_raw query_cqc()s a CQN after DESTROY_CQC/hns_roce_table_put. That is a UAF read of freed CQ backing store.\nI:H - The same window leaves vendor CQ allocations (c4iw cq->queue/sw_queue, hns mtr after hns_roce_mtr_destroy, mlx5 cq->buf.umem after ib_umem_release, bnxt hwq PBLs after bnxt_qplib_free_hwq) freed while the ib_cq remains in the restrack xarray. Reclaiming those objects while fill_res_cq_entry/vendor ops still run is a UAF write/control-flow primitive.\nA:H - fill_res_cq_entry and vendor fill (c4iw_fill_res_cq_entry dereferencing dma-freed cq->queue, hns/mlx5/bnxt querying a destroyed CQN) run after destroy_cq has released those resources, so the race oopses the kernel, and repeating create_cq/destroy_cq against concurrent RDMA_NLDEV_CMD_RES_CQ_GET panics the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/verbs.c"],"versions":[{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"42f7a0c7a94003059540cce448acabfa62ad119d","status":"affected","versionType":"git"},{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"253c2ed71a532c70fa0e64317ceb02bb1a50c84c","status":"affected","versionType":"git"},{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"b85a148731eceffacb6a030950187d785175607f","status":"affected","versionType":"git"},{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"197c262dbf94c0f7ab7ac54b66f892ce9f343232","status":"affected","versionType":"git"},{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"8a72a6aad84b3928dbb5e564bff1f56a7ec222ae","status":"affected","versionType":"git"},{"version":"08f294a1524bc3211a28091daa6c7513828c7d33","lessThan":"3481bec4dfc4aee24ffea5a547ee95b70b67d9d5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/verbs.c"],"versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.16","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/42f7a0c7a94003059540cce448acabfa62ad119d"},{"url":"https://git.kernel.org/stable/c/253c2ed71a532c70fa0e64317ceb02bb1a50c84c"},{"url":"https://git.kernel.org/stable/c/b85a148731eceffacb6a030950187d785175607f"},{"url":"https://git.kernel.org/stable/c/197c262dbf94c0f7ab7ac54b66f892ce9f343232"},{"url":"https://git.kernel.org/stable/c/8a72a6aad84b3928dbb5e564bff1f56a7ec222ae"},{"url":"https://git.kernel.org/stable/c/3481bec4dfc4aee24ffea5a547ee95b70b67d9d5"}],"title":"RDMA/core: Fix potential use after free in ib_destroy_cq_user()","x_generator":{"engine":"bippy-1.2.0"}}}}