SB20260918210 - Use-after-free in Linux kernel infiniband core driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-92511)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to a use-after-free in ib_destroy_cq_user() when accessing a completion queue through the netlink path during its destruction. A local user can access a completion queue through netlink while it is being destroyed to trigger a use-after-free condition.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/197c262dbf94c0f7ab7ac54b66f892ce9f343232
- https://git.kernel.org/stable/c/253c2ed71a532c70fa0e64317ceb02bb1a50c84c
- https://git.kernel.org/stable/c/3481bec4dfc4aee24ffea5a547ee95b70b67d9d5
- https://git.kernel.org/stable/c/42f7a0c7a94003059540cce448acabfa62ad119d
- https://git.kernel.org/stable/c/8a72a6aad84b3928dbb5e564bff1f56a7ec222ae
- https://git.kernel.org/stable/c/b85a148731eceffacb6a030950187d785175607f