CVE-2026-90308 PUBLISHED

RDMA/erdma: Hold QP references for AE and CM processing

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Hold QP references for AE and CM processing

AE QP fatal events and iWARP CM paths load QPs from dev->qp_xa and then use or reference them outside the xarray lock. erdma_destroy_qp() can drop the destroy-path reference and free QP resources while such a lookup is in flight.

Add erdma_qp_get_by_qpn() to acquire a kref under the xarray lock with kref_get_unless_zero(). Remove the QP from the xarray before dropping the destroy-path reference so no new lookup can acquire it while destruction waits for existing users.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 155055771704f8cbb5c176a4309b7dc30a50450c to 6e32f84b63c054e09392153125d7202abab2d14b (excl.)
  • affected from 155055771704f8cbb5c176a4309b7dc30a50450c to ec987c0654651036dad6a42f7fa2a6d7c16a3687 (excl.)
  • affected from 155055771704f8cbb5c176a4309b7dc30a50450c to c92686867638cda954fdb2bdbac8a75e3aa6eaae (excl.)
  • affected from 155055771704f8cbb5c176a4309b7dc30a50450c to a52eeff32024f190b3bdc99088c7becccd4fa60b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.0 is affected
  • unaffected from 0 to 6.0 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References