Race condition in Linux kernel - CVE-2026-93107
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and corrupt data.
The vulnerability exists due to a race condition in the RDMA RXE responder state machine's do_complete function when a queue pair enters the error state while completing a received packet. A remote attacker can send a packet while a disconnect races with receive processing to cause a denial of service and corrupt data.
Affected software
How to mitigate CVE-2026-93107
External References
- https://git.kernel.org/stable/c/0d37e2503efd1069a74be740eadf63ea17c96810
- https://git.kernel.org/stable/c/15ae32c4a3551c4c9da457370bdfdd65d171e512
- https://git.kernel.org/stable/c/399713f1f0eac641351c8ceaec0ab8244ddcf78c
- https://git.kernel.org/stable/c/62a4b48767e06fdd64548450fae2b1ffc6ff5d69
- https://git.kernel.org/stable/c/c319b986a88cedf600c4497cd7814a891b2f9e7c