Database/Kernel, userspace & hypervisor
Linux kernel RDMA/rxe: MR re-registration swaps the PD before validating access flags, freeing a live PD
Impact
rxe_rereg_user_mr() reassigns mr->ibmr.pd and only afterwards rejects unsupported IB_MR_REREG_ACCESS bits, so a caller can return an error with the protection domain already swapped. The core only adjusts pd->usecnt on the success path, so the MR ends up pointing at the new PD while the usecnts still charge it to the original; deregistering the MR then drops the new PD's count to zero while a memory window still references it, and rxe_mw_cleanup() writes into freed memory. The KASAN trace in the commit shows the use-after-free reached entirely from uverbs calls one unprivileged process can make. On a shared GPU node that is a local kernel-memory corruption primitive, and recovering a node that hits it means an unplanned drain mid-job.
Who can reach it
Local user with access to the RDMA uverbs character devices - the whole sequence (alloc PD, reg MR, rereg with a bad access mask, dereg, dealloc MW) is ordinary unprivileged userspace API use. Not reachable remotely and not reachable at all on hosts that do not load the rxe driver.
What to do
Apply the stable kernel fix (five stable commits listed) and reboot the node; kernel RDMA core changes cannot be hot-patched here. If soft-RoCE is not in use, unloading or blacklisting rxe removes the exposure. No fixed mainline release number is given in the record - map the commit onto your stable branch.
References
Related entries
- Linux kernel RDMA/siw: failed QP modify in siw_accept() races QP-to-ERROR transition into a use-after-freeCVE-2026-98367 · Linux kernel RDMA/siw siw_accept() (CEP association cleared outside state_lock)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.