-
CVE-2026-93104
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:11:15
- Zuletzt bearbeitet 17.09.2026 17:18:04
- Erkennungen
RDMA/rvt: Return NULL after port allocation failure
In the Linux kernel, the following vulnerability has been resolved: RDMA/rvt: Return NULL after port allocation failure rvt_alloc_device() deallocates the IB device when its port array cannot be allocated but then returns the pointer to the released allocation. Callers treat any non-NULL value as valid and dereference it, resulting in a use-after-free. Return NULL immediately after deallocation so callers can propagate the allocation failure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ff6acd69518e0a84bd9c9b7f1bd4313f7076db97
Version <
b1e1b25723af44328524c7b54433e4bf0ab9930c
Status
affected
Version
ff6acd69518e0a84bd9c9b7f1bd4313f7076db97
Version <
2982eaf3b9d2d953318c74cd6f1b7576ea6d7b1f
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.6
Status
affected
Version
0
Version <
4.6
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/b1e1b25723af44328524c7b54433e4bf0ab9930c
https://git.kernel.org/stable/c/2982eaf3b9d2d953318c74cd6f1b7576ea6d7b1f