-

CVE-2026-72468

xprtrdma: Initialize re_id before removal registration

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Initialize re_id before removal registration

rpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client
before returning the new rdma_cm_id to rpcrdma_ep_create(). However
rpcrdma_ep_create() currently stores that pointer in ep->re_id only
after rpcrdma_create_id() returns.

A local administrator can race an NFS/RDMA mount against RDMA device
removal. If rpcrdma_remove_one() observes the just-registered
notification before rpcrdma_ep_create() assigns ep->re_id,
rpcrdma_ep_removal_done() calls trace_xprtrdma_device_removal(NULL).
The tracepoint dereferences id->device->name and copies
id->route.addr.dst_addr, so the callback can crash the kernel with a
NULL pointer dereference.

Store the rdma_cm_id in ep->re_id immediately before publishing
ep->re_rn. The existing error path still destroys the id directly if
registration fails; ep is then freed by the caller without using
ep->re_id. Remove the later duplicate assignment in rpcrdma_ep_create().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3f4eb9ff923413cdb4c7e171c06d3564f6286712
Version < 51248d877bbc6e604e38aeaf776c2781cb4f0dbd
Status affected
Version 3f4eb9ff923413cdb4c7e171c06d3564f6286712
Version < 28743571c17b58c21a7216fc9faaf8028df5869b
Status affected
Version 3f4eb9ff923413cdb4c7e171c06d3564f6286712
Version < 264ccd7871915749bee55fe0c39467a7f08d5479
Status affected
Version 3f4eb9ff923413cdb4c7e171c06d3564f6286712
Version < bb7caa63e1db22fd03e8dc591b12169e99169dff
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/51248d877bbc6e604e38aeaf776c2781cb4f0dbd
https://git.kernel.org/stable/c/28743571c17b58c21a7216fc9faaf8028df5869b
https://git.kernel.org/stable/c/264ccd7871915749bee55fe0c39467a7f08d5479
https://git.kernel.org/stable/c/bb7caa63e1db22fd03e8dc591b12169e99169dff