Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80864— RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于RDMA/rxe的rxe_qp_from_attr()在IB_QP_STATE路径之外处理IB_QP_MAX_DEST_RD_ATOMIC属性时未持有state_lock,释放并重新分配qp->resp.resources[]资源,留下悬空指针,造成释放后重用,本地非特权用户可利用该漏洞导致本地拒绝服务。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.16% · P5

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 8700e3e7c4857d28ebaa824509934556da0b3e76< 0136b528b753c5a56e4d997ef20b86bb6750b8fb affected
8700e3e7c4857d28ebaa824509934556da0b3e76< ffa4f0be69656be1755090f02db38d49816585c6 affected
8700e3e7c4857d28ebaa824509934556da0b3e76< d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844 affected
8700e3e7c4857d28ebaa824509934556da0b3e76< 60dfd47929cd1e7070daa810d40ce538d888410d affected
8700e3e7c4857d28ebaa824509934556da0b3e76< 6f7014237405e7f032b5c53a82d9eccf6161c291 affected
4.8 affected
< 4.8 unaffected
6.12.108≤ 6.12.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80864

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and runs while the responder task rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting only that attribute calls free_rd_atomic_resources() then alloc_rd_atomic_resources(), swapping qp->resp.resources[] while rxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources() also leaves the cached pointer qp->resp.res dangling. A local unprivileged user can race the free/realloc into a use-after-free in rxe_receiver() (local DoS). Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(), as rxe_qp_reset() already does when tearing this array down, re-enabling only after alloc_rd_atomic_resources() succeeds so the responder never resumes against a NULL qp->resp.resources on the ENOMEM path. Also clear qp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c completion paths. Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于RDMA/rxe的rxe_qp_from_attr()在IB_QP_STATE路径之外处理IB_QP_MAX_DEST_RD_ATOMIC属性时未持有state_lock,释放并重新分配qp->resp.resources[]资源,留下悬空指针,造成释放后重用,本地非特权用户可利用该漏洞导致本地拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8700e3e7c4857d28ebaa824509934556da0b3e76 ~ 0136b528b753c5a56e4d997ef20b86bb6750b8fb -
Linux Linux 4.8 -

II. Public POCs for CVE-2026-80864

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80864

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80864 (5)

Same Patch Batch · Linux · 2026-09-04 · 156 CVEs total

CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free
CVE-2026-80858 fuse: publish io-uring queues with release semantics
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness
CVE-2026-80860 fuse: fix race between interrupt and resend
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources()
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
CVE-2026-80874 arm64: dts: renesas: ironhide: Describe inline ECC carveouts
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net()
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
CVE-2026-80854 usb: gadget: f_tcm: keep port count until LUN teardown completes
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount()

Showing top 20 of 156 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80864

No comments yet


Leave a comment