Use-after-free in Linux kernel - CVE-2026-90308
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in RDMA/erdma QP handling when AE QP fatal events or iWARP CM paths process QPs concurrently with QP destruction. A local user can cause a QP to be destroyed while AE or CM processing is in progress to cause a denial of service.