๐Ÿ” CVE Alert

CVE-2026-100075

CRITICAL 9.8

RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < af00051dbc9f467d4840ec709680660a3f8990fa b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < 717ab4d0614e9446bf8e2de6229464499e4008d6 b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < f1f2252da52cdda912da9993f39f58783b01b38f b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < be1478849e1abb1e12dc12e14cdbf800cc6fa99a b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < af073bd245180393bcb15d33d3990a6bdc32593a b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < bd02d644bd19a2795c018635d273d91e45d2bb95 b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < b38f98e176050850f41bb6415f3a71400056623e
Linux / Linux
4.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/af00051dbc9f467d4840ec709680660a3f8990fa git.kernel.org: https://git.kernel.org/stable/c/717ab4d0614e9446bf8e2de6229464499e4008d6 git.kernel.org: https://git.kernel.org/stable/c/f1f2252da52cdda912da9993f39f58783b01b38f git.kernel.org: https://git.kernel.org/stable/c/f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d git.kernel.org: https://git.kernel.org/stable/c/be1478849e1abb1e12dc12e14cdbf800cc6fa99a git.kernel.org: https://git.kernel.org/stable/c/af073bd245180393bcb15d33d3990a6bdc32593a git.kernel.org: https://git.kernel.org/stable/c/bd02d644bd19a2795c018635d273d91e45d2bb95 git.kernel.org: https://git.kernel.org/stable/c/b38f98e176050850f41bb6415f3a71400056623e