Answer in brief
CVE-2026-92508 records a Unknown severity vulnerability in RDMA/core: Fix potential use after free in ib_free_cq(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <a804b162f9bc2b38b2ed1b4752eea9faadb1645b || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <91f8a17a22ab615a03743120e19935e731f28fb9 || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <76f2cb4f721815c3b6262a6dc2151de88646924c || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <b8dcca427096fc9c50f1b376847fea72bc842d31 || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <9abea37942534eeb049335476178696b654b000c || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <43403fe45379c64fa6276e5a8ede44493e5d2d3d || >=43d781b9fa562f0c6e50f62c870fbfeb9dc85213 <29dc2f8e1c97372c2871a70088707933515fbd5b || 7ac277a01f9017fcde4f3f81670c995992945433 || 093f87dda065e0f618dd577985eccbe85efb9b54 || >=5.8.17 <5.9 || >=5.9.2 <5.10 | a804b162f9bc2b38b2ed1b4752eea9faadb1645b, 91f8a17a22ab615a03743120e19935e731f28fb9, 76f2cb4f721815c3b6262a6dc2151de88646924c, b8dcca427096fc9c50f1b376847fea72bc842d31, 9abea37942534eeb049335476178696b654b000c, 43403fe45379c64fa6276e5a8ede44493e5d2d3d, 29dc2f8e1c97372c2871a70088707933515fbd5b, 5.9, 5.10 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_cq() When accessing a CQ via the netlink path the only synchronization mechanism for the said CQ is rdma_restrack_get(). Currently, rdma_restrack_del() is invoked at the end of ib_free_cq(), which is too late, since by that point vendor-specific resources associated with the CQ might already be freed. This can leave a short window where the CQ remains accessible through restrack, leading to a potential use-after-free. Fix this by moving the rdma_restrack_del() call to be before the freeing of the vendor-specific resources ensuring that the CQ is removed from restrack before its internal resources are released. This guarantees that no new users hold references to a CQ that is in the process of destruction.
Quoted source text, attributed separately from HOL analysis.