Linux Kernel Vulnerability Affecting RDMA Responder in Communication
CVE-2026-80864
What is CVE-2026-80864?
An identified vulnerability in the Linux kernel involves a use-after-free condition in RDMA (Remote Direct Memory Access) responders. The rxe_qp_from_attr() function improperly handles the IB_QP_MAX_DEST_RD_ATOMIC attribute outside the IB_QP_STATE path, leading to potential unauthorized memory access. This flaw allows a local, unprivileged user to exploit the race condition during resource allocation, resulting in a denial of service. Proper safeguards are required to manage task drain and resource management to prevent the system from operating against a null memory reference during critical operations.
Affected Version(s)
Linux 8700e3e7c4857d28ebaa824509934556da0b3e76 < 0136b528b753c5a56e4d997ef20b86bb6750b8fb
Linux 8700e3e7c4857d28ebaa824509934556da0b3e76
Linux 8700e3e7c4857d28ebaa824509934556da0b3e76