CVE-2026-80864
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and runs while the responder task rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting only that attribute calls free_rd_atomic_resources() then alloc_rd_atomic_resources(), swapping qp->resp.resources[] while rxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources() also leaves the cached pointer qp->resp.res dangling. A local unprivileged user can race the free/realloc into a use-after-free in rxe_receiver() (local DoS).
Leer descripción completaMostrar menos
Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(), as rxe_qp_reset() already does when tearing this array down, re-enabling only after alloc_rd_atomic_resources() succeeds so the responder never resumes against a NULL qp->resp.resources on the ENOMEM path. Also clear qp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c completion paths.
Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0136b528b753c5a56e4d997ef20b86bb6750b8fb
- https://git.kernel.org/stable/c/60dfd47929cd1e7070daa810d40ce538d888410d
- https://git.kernel.org/stable/c/6f7014237405e7f032b5c53a82d9eccf6161c291
- https://git.kernel.org/stable/c/d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844
- https://git.kernel.org/stable/c/ffa4f0be69656be1755090f02db38d49816585c6
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80864",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"lessThan": "0136b528b753c5a56e4d997ef20b86bb6750b8fb",
"versionType": "git"
},
{
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"lessThan": "ffa4f0be69656be1755090f02db38d49816585c6",
"versionType": "git"
},
{
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"lessThan": "d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844",
"versionType": "git"
},
{
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"lessThan": "60dfd47929cd1e7070daa810d40ce538d888410d",
"versionType": "git"
},
{
"status": "affected",
"version": "8700e3e7c4857d28ebaa824509934556da0b3e76",
"lessThan": "6f7014237405e7f032b5c53a82d9eccf6161c291",
"versionType": "git"
}
],
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_qp.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/infiniband/sw/rxe/rxe_qp.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:15.737",
"references": [
{
"url": "https://git.kernel.org/stable/c/0136b528b753c5a56e4d997ef20b86bb6750b8fb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/60dfd47929cd1e7070daa810d40ce538d888410d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6f7014237405e7f032b5c53a82d9eccf6161c291",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ffa4f0be69656be1755090f02db38d49816585c6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp\n\nrxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the\nIB_QP_STATE path, so it holds no state_lock and runs while the responder\ntask rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting\nonly that attribute calls free_rd_atomic_resources() then\nalloc_rd_atomic_resources(), swapping qp->resp.resources[] while\nrxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources()\nalso leaves the cached pointer qp->resp.res dangling. A local\nunprivileged user can race the free/realloc into a use-after-free in\nrxe_receiver() (local DoS).\n\nDrain recv_task around the swap with rxe_disable_task()/rxe_enable_task(),\nas rxe_qp_reset() already does when tearing this array down, re-enabling\nonly after alloc_rd_atomic_resources() succeeds so the responder never\nresumes against a NULL qp->resp.resources on the ENOMEM path. Also clear\nqp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c\ncompletion paths.\n\nReproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone."
}
],
"lastModified": "2026-09-04T16:18:15.737",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}