Not scored yet

CVE-2026-92513

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial table insertion mana_table_store_ud_qp() publishes a QP at its send-queue id before inserting the receive-queue id, dropping the XArray lock between the two xa_insert_irq() calls. A concurrent completion handler can look up the QP and take a transient reference. When the second insertion fails, the rollback erased only the send-queue entry and returned, leaving both the initial table reference and the transient reference outstanding while RDMA core frees the QP, causing a use-after-free. Drain the reference as normal destruction does: drop the initial reference and wait for qp->free, releasing the QP only after every concurrent lookup returns its reference.

What this means for your business

    What to do

    1. 1Ask your IT team or provider whether any of your systems use the affected product.
    2. 2If you do, follow the vendor's guidance. No patch reference has been published yet.

    Not sure if your company is exposed?

    Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.

    Scoring

    CVSS
    Not yet scored
    Assigned by
    416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Dates

    Published
    2026-09-17
    Last modified
    2026-09-17
    Sources
    NVD

    References