CVE-2026-92510

Source
https://cve.org/CVERecord?id=CVE-2026-92510
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92510.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92510
Downstream
Published
2026-09-17T16:10:20Z
Modified
2026-09-18T03:48:40Z
Summary
RDMA/core: Fix potential use after free in ib_destroy_srq_user()
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Fix potential use after free in ib_destroy_srq_user()

When accessing a SRQ via the netlink path the only synchronization mechanism for the said SRQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_destroy_srq_user(), which is too late, since by that point vendor-specific resources associated with the SRQ might already be freed. This can leave a short window where the SRQ remains accessible through restrack, leading to a potential use-after-free.

Fix this by moving the rdma_restrack_begin_del() call to the start of ib_destroy_srq_user(), ensuring that the SRQ is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a SRQ that is in the process of destruction.

In addition, this change preserves the intended inverted order between create and destroy routines: resources are added to restrack at the end of successful creation, and hence shall be removed from the restrack first thing during the destruction flow, which keeps the lifecycle management consistent and predictable.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92510.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
48f8a70e899fa4d9c8f00369f482f0382173ece9
Fixed
a5bfd9fe05d5cebbd3e447bf7f7b2c663007d8b9
Fixed
d3d0eabe6e39b024deb3e085e2d408d037e967c3
Fixed
9c704383529044c02122f85a2a9a42cbf14a07a6
Fixed
bedd7dee72588c838f5b67197ea8b387e7beb918
Fixed
95c992c869df54a6a7061f5f3fb6400244f2af8f
Fixed
88244ecc71cc0b3ed200f5ef7ddea6686adfd730

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92510.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92510.json"