SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-64033

CRITICAL · CVSS 9.8 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the RDMA/rtrs subsystem, where improper cleanup during the path file creation process can lead to a use-after-free condition. This flaw allows an attacker to exploit the dereferencing of freed memory, potentially leading to arbitrary code execution or system crashes. Organizations using Linux systems with RDMA capabilities should prioritize patching this critical vulnerability to mitigate the associated risks.

CVE
CVE-2026-64033
Severity
CRITICAL
CVSS
9.8
EPSS
0.49%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Fix use-after-free in path file creation cleanup In the error path of rtrs_srv_create_path_files(), the sysfs root folders may already have been created and srv_path->kobj may already have been initialized. If a later step fails, the cleanup currently calls kobject_put(&srv_path->kobj) before rtrs_srv_destroy_once_sysfs_root_folders(srv_path). kobject_put() may drop the last reference to srv_path->kobj and invoke the release callback, rtrs_srv_release(), which frees srv_path. The following call to rtrs_srv_destroy_once_sysfs_root_folders(srv_path) then dereferences srv_path internally to access srv_path->srv, resulting in a use-after-free. This failure path is reached before rtrs_srv_create_path_files() returns success, so the successful-path lifetime handling is not involved. Fix this by destroying the sysfs root folders before calling kobject_put(&srv_path->kobj), so srv_path is still valid while the helper accesses it. This issue was found by a static analysis tool I am developing.