Use-after-free in Linux kernel - CVE-2026-90292
Published: September 18, 2026
Vulnerability identifier: #VU151189
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90292
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a use-after-free condition.
The vulnerability exists due to improper reference counting in the RDMA/siw siw_accept() function when handling a userspace-supplied queue pair that is already in the RTS state. A local user can supply such a queue pair to cause a use-after-free condition.
Affected software
Linux kernel
How to mitigate CVE-2026-90292
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/561651d6a15588cee2040755f253faca2463415c
- https://git.kernel.org/stable/c/59de5502f32895ffe9c45530327ed997b90fdf06
- https://git.kernel.org/stable/c/8f286a8094ee32c415f9ecd2c20765beb8a18c79
- https://git.kernel.org/stable/c/a89d120615e711ce8fce551fd291c2f387666735
- https://git.kernel.org/stable/c/a9394971825933074032794a5feee5211509c774
- https://git.kernel.org/stable/c/b9e7d3d9fdb2bfcfb25d93529fdf766536b37c78
- https://git.kernel.org/stable/c/d57db36e74cca4763e1c2c0c6eb9f84d19813879
- https://git.kernel.org/stable/c/de603f01d9ccf823e575b013ffd86ebedca9a8c5