Use-after-free in Linux kernel - CVE-2026-90309
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the ERDMA completion queue handling when EQ handlers invoke completion or error callbacks after a completion queue has been destroyed. A local user can race completion queue destruction with EQ event processing to cause a denial of service.
Affected software
How to mitigate CVE-2026-90309
External References
- https://git.kernel.org/stable/c/05b8ca493dd02319bca93c640b259c2ba51ef321
- https://git.kernel.org/stable/c/1fc9c1933959d2776a1ce7bf424251b8b5b586cd
- https://git.kernel.org/stable/c/4545f355654d044d35a31cd01cc46f491a8a7c36
- https://git.kernel.org/stable/c/610ef81797bb4f709e8675c1d8d093bb9ccdcbd8
- https://git.kernel.org/stable/c/98df2aee1459ee1c62c70cbe9b370d2a532aea36
- https://git.kernel.org/stable/c/c0a83f29a24c7e7f8516630848ef6db4c174deed