๐Ÿ” CVE Alert

CVE-2026-90423

UNKNOWN 0.0

RDMA/rxe: Fix UAF in ODP init error-handling path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails, rxe_odp_mr_init_user() releases umem_odp and returns an error. rxe_reg_user_mr() then unwinds the error through rxe_cleanup(), rxe_mr_cleanup(), ib_umem_release(mr->umem). There is an IS_ERR_OR_NULL(umem) check at the start of ib_umem_release(). But since mr->umem is NOT reset to NULL in the error handling path of rxe_odp_mr_init_user(), the check passes and it reads already-freed fields like umem->is_dmabuf, causing UAF. Fix the UAF by clearing mr->umem after releasing the failed ODP umem so the MR cleanup path does not release it again.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91 < 5f1933163327c9f1c8f2a341c6cb551aaf231ff9 d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91 < 4cfb448705da3171d44d9cbe7be53ff03284d532 d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91 < 51f2c8d2c99fc1f452f7113c08a35edcc4bf8732
Linux / Linux
6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5f1933163327c9f1c8f2a341c6cb551aaf231ff9 git.kernel.org: https://git.kernel.org/stable/c/4cfb448705da3171d44d9cbe7be53ff03284d532 git.kernel.org: https://git.kernel.org/stable/c/51f2c8d2c99fc1f452f7113c08a35edcc4bf8732