๐Ÿ” CVE Alert

CVE-2026-98352

UNKNOWN 0.0

RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted The client borrows shared CQ credits in the ADDR_RESOLVED handler via ib_cq_pool_get(), before the peer is connected. create_cm() can return -ERESTARTSYS from wait_event_interruptible_timeout() without destroying the CM ID. The init_conns() and stop-and-destroy paths then call destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards rdma_destroy_id(). CMA serializes the handler against rdma_destroy_id() with handler_mutex, but that does not order the GET against destroy_con_cq_qp(). If ADDR_RESOLVED has already passed the DESTROYING check, it can take con_mutex, GET credits, and then lose the con to kfree. Device unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup(). Set a per-connection flag under con_mutex before CQ/QP teardown so a racing ADDR_RESOLVED cannot borrow credits after teardown has begun.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3b89e92c2a95a39c38a3808f4528e502a39bd94d < a82cca40139d9fcae8208901856bd5bb4051f097 3b89e92c2a95a39c38a3808f4528e502a39bd94d < 74c4ed55e61f1b65ddbebc5b635d136461a1c3da 3b89e92c2a95a39c38a3808f4528e502a39bd94d < 6f8020fe7465f49e234a576c04e415e9d08c7878 3b89e92c2a95a39c38a3808f4528e502a39bd94d < 31024e158b45358370a0a14ed96589e6aa62d6cb 3b89e92c2a95a39c38a3808f4528e502a39bd94d < 8f253d5893f991742464b9e7203c43fc08d0aa11 3b89e92c2a95a39c38a3808f4528e502a39bd94d < bf88ac4867050112a6c819c8d1a7209bf48ef427 3b89e92c2a95a39c38a3808f4528e502a39bd94d < 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda
Linux / Linux
5.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a82cca40139d9fcae8208901856bd5bb4051f097 git.kernel.org: https://git.kernel.org/stable/c/74c4ed55e61f1b65ddbebc5b635d136461a1c3da git.kernel.org: https://git.kernel.org/stable/c/6f8020fe7465f49e234a576c04e415e9d08c7878 git.kernel.org: https://git.kernel.org/stable/c/31024e158b45358370a0a14ed96589e6aa62d6cb git.kernel.org: https://git.kernel.org/stable/c/8f253d5893f991742464b9e7203c43fc08d0aa11 git.kernel.org: https://git.kernel.org/stable/c/bf88ac4867050112a6c819c8d1a7209bf48ef427 git.kernel.org: https://git.kernel.org/stable/c/2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda