Answer in brief
CVE-2026-90292 records a Unknown severity vulnerability in RDMA/siw: Fix use-after-free in siw_accept(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <d57db36e74cca4763e1c2c0c6eb9f84d19813879 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <59de5502f32895ffe9c45530327ed997b90fdf06 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <a89d120615e711ce8fce551fd291c2f387666735 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <b9e7d3d9fdb2bfcfb25d93529fdf766536b37c78 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <8f286a8094ee32c415f9ecd2c20765beb8a18c79 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <de603f01d9ccf823e575b013ffd86ebedca9a8c5 || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <561651d6a15588cee2040755f253faca2463415c || >=6c52fdc244b5ccc468006fd65a504d4ee33743c7 <a9394971825933074032794a5feee5211509c774 | d57db36e74cca4763e1c2c0c6eb9f84d19813879, 59de5502f32895ffe9c45530327ed997b90fdf06, a89d120615e711ce8fce551fd291c2f387666735, b9e7d3d9fdb2bfcfb25d93529fdf766536b37c78, 8f286a8094ee32c415f9ecd2c20765beb8a18c79, de603f01d9ccf823e575b013ffd86ebedca9a8c5, 561651d6a15588cee2040755f253faca2463415c, a9394971825933074032794a5feee5211509c774 |
| Linux/Linuxgeneric | 5.3 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix use-after-free in siw_accept() siw_accept() looks up the QP supplied by userspace. If that QP is already in RTS, the function jumps to error cleanup before associating the incoming CEP with it. The cleanup tests whether qp->cep is non-NULL and assumes the current call installed the association. However, qp->cep can point to the CEP of an existing connection. The cleanup then drops a reference from the incoming cep, not qp->cep. Once the incoming endpoint loses its remaining references, this can free it before the subsequent cep->qp store, causing a use-after-free. It also clears the existing QP association. Only release the association reference when qp->cep is the incoming CEP. This preserves an existing association and avoids accessing the freed endpoint.
Quoted source text, attributed separately from HOL analysis.