CVE-2026-100075

Source
https://cve.org/CVERecord?id=CVE-2026-100075
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100075.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100075
Downstream
Published
2026-09-25T13:06:47Z
Modified
2026-09-27T03:46:17Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters

When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits.

Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100075.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b99f8e4d7bcd3bfbb3cd965918523299370d0cb2
Fixed
af00051dbc9f467d4840ec709680660a3f8990fa
Fixed
717ab4d0614e9446bf8e2de6229464499e4008d6
Fixed
f1f2252da52cdda912da9993f39f58783b01b38f
Fixed
f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d
Fixed
be1478849e1abb1e12dc12e14cdbf800cc6fa99a
Fixed
af073bd245180393bcb15d33d3990a6bdc32593a
Fixed
bd02d644bd19a2795c018635d273d91e45d2bb95
Fixed
b38f98e176050850f41bb6415f3a71400056623e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100075.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100075.json"