{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93277","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T16:02:15.098Z","datePublished":"2026-09-24T15:52:19.490Z","dateUpdated":"2026-09-25T05:09:56.815Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T05:09:56.815Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Validate udata before executing commands\n\nThe destroy callbacks currently zero the udata output after tearing down\ndriver resources. If the userspace access fails, uverbs preserves the\nuobject and allows the destroy callback to run again, even though the\ndriver resource has already been freed.\n\nCall ib_no_udata_io() before teardown so udata failures are detected\nwhile the resource is still intact, then return success after teardown\ncompletes.\n\nAs part of this change, move ib_respond_empty_udata() to the start of\nthe create and modify flows. While this is not strictly required for\ngeneral create flows, as the core layer unwinds uobjects on failure, it\nis necessary for create AH. In _rdma_create_ah(), the HW object is\notherwise leaked."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled input is the UVERBS_ATTR_UHW_OUT pointer that ib_uverbs_ioctl's UVERBS_METHOD_INVOKE_WRITE copies into attrs->driver_udata; bnxt_re_dereg_mr, bnxt_re_dealloc_pd, bnxt_re_destroy_qp, bnxt_re_destroy_cq and bnxt_re_destroy_srq then clear_user that buffer via ib_respond_empty_udata after teardown. RoCE receive never supplies that udata.\nAC:L - Mapping a PROT_READ/PROT_NONE page and passing it as UHW_OUT on INVOKE_WRITE IB_USER_VERBS_CMD_DEREG_MR (or DEALLOC_PD/DESTROY_QP/CQ/SRQ) makes ib_respond_empty_udata's clear_user fail after bnxt_re_dereg_mr kfree(mr); uverbs_destroy_uobject then keeps uobj->object and a second destroy or close() retries destroy_hw. No race or layout the attacker cannot arrange.\nPR:L - uverbs_devnode() creates /dev/infiniband/uverbs* mode 0666 and ib_uverbs_open() only checks rdma_dev_access_netns(), so an unprivileged process can GET_CONTEXT, REG_MR, then INVOKE_WRITE DEREG_MR without CAP_SYS_ADMIN or init-namespace root.\nUI:N - The attacker opens their own uverbs fd, creates an MR/PD/QP/CQ/SRQ, then issues INVOKE_WRITE destroy with a non-writable UHW_OUT and a follow-up destroy or close(); no other user must mount, open, or click.\nS:U - The double-free is of the host kernel's bnxt_re_mr (kfree in bnxt_re_dereg_mr) and related driver objects (fence->mr, cq->cql, umem). It is local privilege escalation and does not cross a VM, IOMMU, or guest-to-host boundary.\nC:H - bnxt_re_dereg_mr kfree(mr) then returns -EFAULT from ib_respond_empty_udata, so uobj->object still points at the freed bnxt_re_mr; the second destroy_hw walks that slab, and reclaiming it yields an arbitrary kernel read.\nI:H - The same preserved uobject lets the attacker spray the freed bnxt_re_mr (and fence->mr from bnxt_re_destroy_fence_mr on PD destroy, or cq->cql from bnxt_re_destroy_cq) and hijack the second destroy_hw/kfree, which is an arbitrary write and control-flow primitive.\nA:H - Retrying destroy or closing the uverbs fd after the failed ib_respond_empty_udata double-frees mr/cql/umem and re-enters bnxt_qplib_destroy_qp/cq/srq on already-destroyed firmware objects, which oopses or panics the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"versions":[{"version":"bed686d8dcd4fbcaa18cf67468caaf8772acfc7a","lessThan":"c5643ea4f040acc2f4d1e88f49bd0be51110ff2f","status":"affected","versionType":"git"},{"version":"bed686d8dcd4fbcaa18cf67468caaf8772acfc7a","lessThan":"d38c835925d4a3bfdf0a85ff2829ee90c709c561","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.1","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c5643ea4f040acc2f4d1e88f49bd0be51110ff2f"},{"url":"https://git.kernel.org/stable/c/d38c835925d4a3bfdf0a85ff2829ee90c709c561"}],"title":"RDMA/bnxt_re: Validate udata before executing commands","x_generator":{"engine":"bippy-1.2.0"}}}}