๐Ÿ” CVE Alert

CVE-2026-92513

UNKNOWN 0.0

RDMA/mana_ib: drain QP references after partial table insertion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() publishes a QP at its send-queue id before inserting the receive-queue id, dropping the XArray lock between the two xa_insert_irq() calls. A concurrent completion handler can look up the QP and take a transient reference. When the second insertion fails, the rollback erased only the send-queue entry and returned, leaving both the initial table reference and the transient reference outstanding while RDMA core frees the QP, causing a use-after-free. Drain the reference as normal destruction does: drop the initial reference and wait for qp->free, releasing the QP only after every concurrent lookup returns its reference.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8001e9257eca23264550ff9e34598ee43a80f0f9 < 4aaa2ab816c710be7385b31d08373edcdcd71656 8001e9257eca23264550ff9e34598ee43a80f0f9 < 638b9a5364c1482e5d104823c1a3884b3d249484 8001e9257eca23264550ff9e34598ee43a80f0f9 < 97f7c2262c28ebcae64fc957ee978646684a5ed9
Linux / Linux
6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4aaa2ab816c710be7385b31d08373edcdcd71656 git.kernel.org: https://git.kernel.org/stable/c/638b9a5364c1482e5d104823c1a3884b3d249484 git.kernel.org: https://git.kernel.org/stable/c/97f7c2262c28ebcae64fc957ee978646684a5ed9