Race condition in Linux kernel - CVE-2026-45910
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in QP timer handlers in the RDMA rxe subsystem when handling Queue Pair timer callbacks during Queue Pair destruction. A local user can trigger concurrent timer activity and Queue Pair teardown to cause a denial of service.
The issue can lead to a reference count underflow and use-after-free warning during timer handler execution.
How to mitigate CVE-2026-45910
Sources
- https://git.kernel.org/stable/c/3c2ae79fb19dfd67341c14f1e78a5f1744eacfe2
- https://git.kernel.org/stable/c/5ae9da022ee3c97e6469eabcddce9271501ddbad
- https://git.kernel.org/stable/c/756c93d6df7c3bc599f6590b8e5afead6a41de1c
- https://git.kernel.org/stable/c/87bf646921430e303176edc4eb07c30160361b73
- https://git.kernel.org/stable/c/da379ca16af3722f159860d91a99cb6976a7500f