{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93154","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.089Z","datePublished":"2026-09-17T16:11:50.107Z","dateUpdated":"2026-09-18T17:56:16.837Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:56:16.837Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Add refcounting to user ring MRs\n\nPrevent userspace from deregistering the MRs that back QP/CQ/SRQ rings\nby bumping the MR's refcount upon association."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is a local IB_USER_VERBS_CMD_DEREG_MR write (ib_uverbs_dereg_mr / UVERBS_METHOD_MR_DESTROY) on /dev/infiniband/uverbs*. After irdma_get_pbl binds an IRDMA_MEMREG_TYPE_QP/CQ/SRQ ring MR to a live QP/CQ/SRQ, irdma_dereg_mr still frees it; no iWARP/RoCE message supplies that deregistration.\nAC:L - The attacker drives every step with no race: irdma_reg_user_mr with reg_type QP/CQ/SRQ, then irdma_setup_umode_qp/irdma_create_cq/irdma_setup_umode_srq so irdma_get_pbl sets on_list=false, then irdma_dereg_mr. Pre-fix irdma_del_memlist is a no-op on an already-associated ring, so the free is deterministic.\nPR:L - ib_uverbs_open() only checks rdma_dev_access_netns() (devices shared across netns by default) and ib_uverbs_dereg_mr() only requires ownership of the caller's MR uobject, with no capability gate. rdma-core udev rules expose uverbs as 0666; a small ring fits unprivileged RLIMIT_MEMLOCK without CAP_IPC_LOCK.\nUI:N - The attacker registers the ring MR via ib_uverbs_reg_mr, creates the QP/CQ/SRQ, and issues IB_USER_VERBS_CMD_DEREG_MR on that handle from their own process; no other user must mount a device, open a file, or otherwise act.\nS:U - irdma_dereg_mr kfree()s the irdma_mr and releases its umem/HMC PBLEs while the same host's QP/CQ/SRQ still holds iwpbl and the NIC still DMAs those rings. That is host-kernel memory corruption, not a KVM/Xen guest-to-host escape or an IOMMU isolation bypass.\nC:H - irdma_dereg_mr calls ib_umem_release, irdma_free_pble, and kfree(iwmr) while hardware still walks those HMC PBLEs and DMA-reads SQ/RQ/CQ rings. Recycled umem pages and PBLE tables yield device DMA reads of kernel or other-process memory, and iwqp/iwcq->iwpbl dangles into the freed irdma_mr.\nI:H - The NIC keeps DMAing CQEs/WQEs into unpinned, reallocatable ring pages and walking freed PBLE page tables, producing device writes into recycled kernel memory. Combined with the irdma_mr heap UAF (struct irdma_pbl iwpbl is embedded in iwmr), this is an arbitrary-write primitive.\nA:H - kfree of a still-referenced irdma_mr, irdma_free_pble of live HMC page tables, and DMA into unmapped SQ/RQ/CQ pages cause a kernel oops/panic or an irdma CQP/device reset when the QP/CQ/SRQ is next used or destroyed."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/irdma/utils.c","drivers/infiniband/hw/irdma/verbs.c"],"versions":[{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"07974c267f603a76aead348bca97deee95efdcc9","status":"affected","versionType":"git"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"a6c0e693a7c881bfa43ac74cbcad1f8e10f1382b","status":"affected","versionType":"git"},{"version":"b48c24c2d710cf34810c555dcef883a3d35a9c08","lessThan":"f67d8a08f60c9217df6d40da56422d2049f5e334","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/irdma/utils.c","drivers/infiniband/hw/irdma/verbs.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/07974c267f603a76aead348bca97deee95efdcc9"},{"url":"https://git.kernel.org/stable/c/a6c0e693a7c881bfa43ac74cbcad1f8e10f1382b"},{"url":"https://git.kernel.org/stable/c/f67d8a08f60c9217df6d40da56422d2049f5e334"}],"title":"RDMA/irdma: Add refcounting to user ring MRs","x_generator":{"engine":"bippy-1.2.0"}}}}