← Back to search

CVE-2026-100075

9.8 CRITICAL

Published 2026-09-25 · Updated 2026-09-25

AI risk analysis

Summary
This vulnerability in the Linux kernel's RDMA/srpt module can lead to incorrect send queue credit accounting, potentially causing denial of service or other issues if exploited.
Exploitability
Exploitation requires the attacker to trigger the srpt_alloc_rw_ctxs() failure during a multi-buffer indirect descriptor operation, which is relatively complex and depends on specific timing and conditions.
Blast radius
If exploited, the impact is limited to the affected system, potentially leading to service disruption or denial of service conditions.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 5.19.10 or later.
doskernelrdma

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.