OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100075

CRITICAL · CVSS 9.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's RDMA subsystem, specifically in the srpt_alloc_rw_ctxs() function, which improperly handles error conditions during multi-buffer indirect descriptor allocation. This flaw can lead to incorrect accounting of send queue credits, potentially allowing an attacker to exploit the system's resources or disrupt RDMA operations. Organizations using Linux systems with RDMA capabilities should prioritize patching this critical vulnerability to mitigate the risk of resource exhaustion and potential denial-of-service attacks.

CVE
CVE-2026-100075
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.

Related CVEs

Other vulnerabilities affecting the same vendor(s)