CVE-2026-90423

Source
https://cve.org/CVERecord?id=CVE-2026-90423
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90423.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90423
Downstream
Published
2026-09-17T16:09:46Z
Modified
2026-09-18T03:48:38Z
Summary
RDMA/rxe: Fix UAF in ODP init error-handling path
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix UAF in ODP init error-handling path

rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails, rxe_odp_mr_init_user() releases umem_odp and returns an error.

rxe_reg_user_mr() then unwinds the error through rxe_cleanup(), rxe_mr_cleanup(), ib_umem_release(mr->umem). There is an IS_ERR_OR_NULL(umem) check at the start of ib_umem_release(). But since mr->umem is NOT reset to NULL in the error handling path of rxe_odp_mr_init_user(), the check passes and it reads already-freed fields like umem->is_dmabuf, causing UAF.

Fix the UAF by clearing mr->umem after releasing the failed ODP umem so the MR cleanup path does not release it again.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90423.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d03fb5c6599e31b90c6b5f65d43d6ccc6b49eb91
Fixed
5f1933163327c9f1c8f2a341c6cb551aaf231ff9
Fixed
4cfb448705da3171d44d9cbe7be53ff03284d532
Fixed
51f2c8d2c99fc1f452f7113c08a35edcc4bf8732

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90423.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90423.json"