Database/Kernel, userspace & hypervisor
Linux kernel (drivers/net/ethernet/mellanox/mlx4): Shared receive queue objects are looked up from an asynchronous
Impact
Shared receive queue objects are looked up from an asynchronous event handler under RCU, but nothing frees them with RCU and the handler can run against an SRQ that is only half-constructed or already gone. A tenant that creates and destroys SRQs while events land gets a use-after-free on a kernel object - the memory-corruption primitive is inside RDMA connection state, reachable without host privileges.
Who can reach it
A tenant container holding /dev/infiniband/uverbs* on a ConnectX-3 (mlx4) adapter can create and tear down SRQs in a loop while a remote peer on the fabric drives SRQ async events (limit-reached, catastrophic error) against those queues. Requires the mlx4_ib/mlx4_core stack in use; no host root and no VFIO passthrough needed.
What to do
Update to a kernel carrying the fix on your stream. Interim: withhold /dev/infiniband/* from untrusted tenants on mlx4-based nodes, or retire ConnectX-3 hardware from multi-tenant duty.
References
Related entries
- Linux kernel vmw_pvrdma: double free on ucontext allocation error pathCVE-2026-46189 · Linux kernel vmw_pvrdma driver (pvrdma_alloc_ucontext error path)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-46197 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- virtio-win Viosock: integer overflow in the select IOCTL overflows a NonPagedPool array and escalates in the guestCVE-2026-46655 · virtio-win Viosock driver (IOCTL_SELECT, VIOSockSelect bounds check)High
- FreeBSD ZFS: size truncation in ZFS_IOC_USERSPACE_MANY gives a local user a kernel heap overflowCVE-2026-49429 · FreeBSD ZFS (ZFS_IOC_USERSPACE_MANY ioctl)High
- Linux kernel SO_REUSEPORT: cBPF program freed without an RCU grace period, use-after-free in UDP receiveCVE-2026-52910 · Linux kernel net/core sock_reuseport (cBPF program freed without RCU grace period)High
- Linux kernel io_uring poll: cancel flag makes the ownership slowpath unreachableCVE-2026-52933 · Linux kernel io_uring (io_poll_get_ownership signed refcount comparison)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.