CVE-2026-80864
CVE CVE-2026-80864EUVD EUVD-2026-71314Published 2026-09-04T15:55:18.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and runs while the responder task rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting only that attribute calls free_rd_atomic_resources() then alloc_rd_atomic_resources(), swapping qp->resp.resources[] while rxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources() also leaves the cached pointer qp->resp.res dangling. A local unprivileged user can race the free/realloc into a use-after-free in rxe_receiver() (local DoS). Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(), as rxe_qp_reset() already does when tearing this array down, re-enabling only after alloc_rd_atomic_resources() succeeds so the responder never resumes against a NULL qp->resp.resources on the ENOMEM path. Also clear qp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c completion paths. Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 8700e3e7c4857d28ebaa824509934556da0b3e76 <ffa4f0be69656be1755090f02db38d49816585c6; 8700e3e7c4857d28ebaa824509934556da0b3e76 <60dfd47929cd1e7070daa810d40ce538d888410d; 8700e3e7c4857d28ebaa824509934556da0b3e76 <d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844; patch: 6.12.108; 4.8; patch: 7.1.13; patch: 7.2.3; 8700e3e7c4857d28ebaa824509934556da0b3e76 <6f7014237405e7f032b5c53a82d9eccf6161c291; 8700e3e7c4857d28ebaa824509934556da0b3e76 <0136b528b753c5a56e4d997ef20b86bb6750b8fb; patch: 6.18.49; patch: 0; patch: 7.3-rc1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.