Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90219— RDMA/cxgb4: Free debugfs on registration failure

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: RDMA/cxgb4:在注册失败时释放 debugfs c4iw_alloc() 会为每个设备创建 debugfs 目录树(通过 setup_debugfs() 将根目录存储在 dev->debugfs_root 中),但该目录树仅在 c4iw_remove() 中被移除,而未在 c4iw_dealloc() 中处理。当 RDMA 设备注册失败时,注册工作线程的错误处理路径 err_dealloc_ctx 会直接调用 c4iw_dealloc(),从而绕过 c4iw_r

AI Predicted 3.4 Difficulty: Theoretical EPSS 0.23% · P13

Affected Version Matrix 24

VendorProduct Version RangeStatus
Linux Linux 49ea0c036ede81f126f1a9389d377999fdf5c5a1< 459b59f7ed56511d6529311cb4e5e482ebfcfb8e affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< cd60992f09b7e83bfd3c76e3bb06b29f3e2fa0a8 affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< c332d9e7dce234d8bef78271d003a68ee943b61b affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< f98e894ec029a752cf9c7f7834741bead0fb463d affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< 479a7f90060e62bdd9bb4036ec0a70bf460f6d23 affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< 046425412529dbfca1433c8bef5641b271b4ab2a affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< ea41b5630fa3d9877ce9ed8832cf5575f742bfbb affected
49ea0c036ede81f126f1a9389d377999fdf5c5a1< fe5c16bb6252dea6025b748257ddc3b2665495b0 affected
… +16 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90219

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/cxgb4: Free debugfs on registration failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure c4iw_alloc() creates the per-device debugfs tree (dev->debugfs_root via setup_debugfs()), but it is removed only in c4iw_remove(), not in c4iw_dealloc(). When RDMA device registration fails, the registration worker's err_dealloc_ctx path calls c4iw_dealloc() directly, bypassing c4iw_remove(), so the debugfs dentries leak and outlive the freed c4iw_dev. Move debugfs_remove_recursive() into c4iw_dealloc() so every path that frees ctx->dev also removes its debugfs tree.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 49ea0c036ede81f126f1a9389d377999fdf5c5a1 ~ 459b59f7ed56511d6529311cb4e5e482ebfcfb8e -
Linux Linux 5.8 -

II. Public POCs for CVE-2026-90219

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90219

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-90219 (5)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90162 8.8 HIGH ksmbd: defer publishing granted locks to prevent UAF/double-free race
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90219

No comments yet


Leave a comment