7.8

CVE-2026-90423

RDMA/rxe: Fix UAF in ODP init error-handling path

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix UAF in ODP init error-handling path

rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before
calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails,
rxe_odp_mr_init_user() releases umem_odp and returns an error.

rxe_reg_user_mr() then unwinds the error through rxe_cleanup(),
rxe_mr_cleanup(), ib_umem_release(mr->umem). There is an
IS_ERR_OR_NULL(umem) check at the start of ib_umem_release().
But since mr->umem is NOT reset to NULL in the error handling
path of rxe_odp_mr_init_user(), the check passes and it reads
already-freed fields like umem->is_dmabuf, causing UAF.

Fix the UAF by clearing mr->umem after releasing the failed
ODP umem so the MR cleanup path does not release it again.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91
Version < 5f1933163327c9f1c8f2a341c6cb551aaf231ff9
Status affected
Version d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91
Version < 4cfb448705da3171d44d9cbe7be53ff03284d532
Status affected
Version d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91
Version < 51f2c8d2c99fc1f452f7113c08a35edcc4bf8732
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5f1933163327c9f1c8f2a341c6cb551aaf231ff9
https://git.kernel.org/stable/c/4cfb448705da3171d44d9cbe7be53ff03284d532
https://git.kernel.org/stable/c/51f2c8d2c99fc1f452f7113c08a35edcc4bf8732