-

CVE-2026-92513

RDMA/mana_ib: drain QP references after partial table insertion

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana_ib: drain QP references after partial table insertion

mana_table_store_ud_qp() publishes a QP at its send-queue id before
inserting the receive-queue id, dropping the XArray lock between the two
xa_insert_irq() calls. A concurrent completion handler can look up the QP
and take a transient reference. When the second insertion fails, the
rollback erased only the send-queue entry and returned, leaving both the
initial table reference and the transient reference outstanding while RDMA
core frees the QP, causing a use-after-free.

Drain the reference as normal destruction does: drop the initial reference
and wait for qp->free, releasing the QP only after every concurrent lookup
returns its reference.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8001e9257eca23264550ff9e34598ee43a80f0f9
Version < 4aaa2ab816c710be7385b31d08373edcdcd71656
Status affected
Version 8001e9257eca23264550ff9e34598ee43a80f0f9
Version < 638b9a5364c1482e5d104823c1a3884b3d249484
Status affected
Version 8001e9257eca23264550ff9e34598ee43a80f0f9
Version < 97f7c2262c28ebcae64fc957ee978646684a5ed9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4aaa2ab816c710be7385b31d08373edcdcd71656
https://git.kernel.org/stable/c/638b9a5364c1482e5d104823c1a3884b3d249484
https://git.kernel.org/stable/c/97f7c2262c28ebcae64fc957ee978646684a5ed9