Deadlock in Linux kernel - CVE-2026-31565
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock condition in the irdma RDMA subsystem when executing a netdev reset while RDMA applications have active connections. A local user can trigger a netdev reset during active RDMA connections to cause a denial of service.
The issue occurs during device removal in iWARP mode when client cleanup creates a circular dependency involving QP reference counting.
How to mitigate CVE-2026-31565
Sources
- https://git.kernel.org/stable/c/009831768faeca3fb5950ce63f1b49594ec82389
- https://git.kernel.org/stable/c/464bbb844ba5b68e038220c34019069a0a9f1581
- https://git.kernel.org/stable/c/6f52370970ac07d352a7af4089e55e0e6425f827
- https://git.kernel.org/stable/c/a8a1c7621127a15a02494b96ee376406c064237b
- https://git.kernel.org/stable/c/acb060bc2609c2eab49263968be59c7d59d497bc
- https://git.kernel.org/stable/c/adf0de36e52a48681eb58cbd7cbf6c8d200caa2b
- https://git.kernel.org/stable/c/cd8bcec2de5e24e05c34c9391940fda6f50e79b4