Database/Firmware, BMC & network fabric
Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQ
Impact
If the copy_to_user() that returns the SRQ number fails, the queue is freed but the stale pointer is left in srq->rq.queue, and the caller's error path frees it again. A tenant forces the copy to fail by pointing it at an unmapped address - which is entirely under its control - so this is a reliably reachable kernel double free, the classic starting point for heap grooming into privilege escalation on a shared node.
Who can reach it
Local, unprivileged. Create an SRQ on a Soft-RoCE device with a deliberately bad userspace response buffer.
What to do
Kernel update clearing srq->rq.queue after the cleanup. Blacklist rdma_rxe where not needed.
References
Related entries
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionCVE-2026-45910 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure): Once __rds_rdma_map() has handed theCVE-2026-46053 · Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure)High
- Linux kernel (drivers/infiniband/hw/mana): The userspace ABI lets a tenant point several work queues at the sameCVE-2026-46117 · Linux kernel (drivers/infiniband/hw/mana)High
- Linux kernel (drivers/infiniband/hw/mana): The RSS hash-key length arrived from the userspace ABI structure and wentCVE-2026-46145 · Linux kernel (drivers/infiniband/hw/mana)High
- Linux kernel (drivers/infiniband/hw/mlx5): If the second of the two device-wide shared SRQs fails to allocate, theCVE-2026-46176 · Linux kernel (drivers/infiniband/hw/mlx5)High
- Linux kernel RDMA core (ib_umem / IB_MR_REREG_ACCESS re-registration): An RDMA memory region registered read-only canCVE-2026-52908 · Linux kernel RDMA core (ib_umem / IB_MR_REREG_ACCESS re-registration)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.