High · published May 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix double free in rxe_srq_from_init
In rxe_srq_from_init(), the queue pointer 'q' is assigned to
'srq->rq.queue' before copying the SRQ number to user space.
If copy_to_user() fails, the function calls rxe_queue_cleanup()
to free the queue, but leaves the now-invalid pointer in
'srq->rq.queue'.
The caller of rxe_srq_from_init() (rxe_create_srq) eventually
calls rxe_srq_cleanup() upon receiving the error, which triggers
a second rxe_queue_cleanup() on the same memory, leading to a
double free.
The call trace looks like this:
kmem_cache_free+0x.../0x...
rxe_queue_cleanup+0x1a/0x30 [rdma_rxe]
rxe_srq_cleanup+0x42/0x60 [rdma_rxe]
rxe_elem_release+0x31/0x70 [rdma_rxe]
rxe_create_srq+0x12b/0x1a0 [rdma_rxe]
ib_create_srq_user+0x9a/0x150 [ib_core]
Fix this by moving 'srq->rq.queue = q' after copy_to_user.
| Product | Versions | Fixed in |
|---|---|---|
| linux/linux_kernel | ≥ 4.19.86, < 5.10.259 | 5.10.259 |
| linux/linux_kernel | ≥ 5.11, < 5.15.210 | 5.15.210 |
| linux/linux_kernel | ≥ 5.16, < 6.1.176 | 6.1.176 |
| linux/linux_kernel | ≥ 6.2, < 6.6.128 | 6.6.128 |
| linux/linux_kernel | ≥ 6.7, < 6.12.75 | 6.12.75 |
| linux/linux_kernel | ≥ 6.13, < 6.18.14 | 6.18.14 |
| linux/linux_kernel | ≥ 6.19, < 6.19.4 | 6.19.4 |