RDMA/erdma: complete object teardown when the destroy command fails
Summary
| CVE | CVE-2026-92488 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:50 UTC |
| Updated | 2026-09-17 17:17:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
RDMA/erdma: complete object teardown when the destroy command fails
erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and
erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed,
leaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN
identifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and
permanently disables the command queue, so no retry can succeed; the RDMA
core keeps the object after a failed destructor and forced uverbs cleanup
then nulls the pointers, making the resources unreachable.
Warn on failure but release every software-owned resource and return
success, since during terminal destruction the hardware command result is
only diagnostic. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 155055771704f8cbb5c176a4309b7dc30a50450c 5fcfc988ecf3e2bbe308b95c2c0d2f011d9afabe git |
Not specified |
| CNA |
Linux |
Linux |
affected 155055771704f8cbb5c176a4309b7dc30a50450c ce7d205c264665517c25e8a3231cf2d0c2443e3c git |
Not specified |
| CNA |
Linux |
Linux |
affected 155055771704f8cbb5c176a4309b7dc30a50450c 334145d683ad3e31d052247f10807f2ebc950351 git |
Not specified |
| CNA |
Linux |
Linux |
affected 155055771704f8cbb5c176a4309b7dc30a50450c 652befcba956ef357f480525ccbe25c59bc81d4d git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.0 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.0 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/ce7d205c264665517c25e8a3231cf2d0c2443e3c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/652befcba956ef357f480525ccbe25c59bc81d4d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5fcfc988ecf3e2bbe308b95c2c0d2f011d9afabe |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/334145d683ad3e31d052247f10807f2ebc950351 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.