SB20260918211 - Use-after-free in Linux kernel infiniband core driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-92512)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a kernel crash.
The vulnerability exists due to use-after-free in ib_query_qp() when querying a queue pair through the RDMA netlink flow while the queue pair is being destroyed. A local user can send a netlink request to query the queue pair during its destruction to cause a kernel crash.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/001383248e5d754bbddb7ae2a8573bc8501c85d8
- https://git.kernel.org/stable/c/038cf231b7099ba6202dcc0c1ea01525122df09f
- https://git.kernel.org/stable/c/2ef2ea52ae41bd9efa83139e97ae839de7e17156
- https://git.kernel.org/stable/c/709ba0e5311bd034eb4d9c1c00cc4e1109d6dc3e
- https://git.kernel.org/stable/c/8998829739c31fdbc892078e4449887d902e5dc9
- https://git.kernel.org/stable/c/a608af8cde3dd38936b356bbdeedea0653a05b3f