KernelScan.io

CRITICAL Introduced in 4.7

srpt RwCtxs UAF

CVE-2026-100075

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.7HIGH

01

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.

02

Engine v0.6.0

Risk summary

Systems running the kernel SRP target driver over RDMA (InfiniBand or RoCE) are at risk from an remote attacker on the same fabric who can trigger a use-after-free via crafted SCSI commands, potentially achieving kernel memory corruption, code execution, or denial of service. The vulnerability requires only network access to the RDMA fabric, not local operating-system privileges.

Affecteddrivers/infiniband/ulp/srpt/ib_srpt.c (RDMA SRP target)

Vulnerability analysis

When the SRP target driver allocates RDMA transfer contexts for a multi-buffer command and the allocation fails partway through, the error cleanup frees the allocated memory but leaves stale accounting counters and a dangling pointer in the command context. Later queue-credit accounting subtracts incorrect values, and the dangling pointer may be dereferenced when the context is reused, corrupting kernel heap memory. The fix saves the original counter values before allocation begins and, on failure, restores them and clears the pointer after freeing, returning the context to a clean state. An attacker with access to the RDMA fabric can trigger this by sending a crafted multi-buffer SCSI command that causes a partial allocation failure; no operating-system privileges are needed beyond fabric access.

03

BranchIntroducedFixed inPatch commit
5.104.75.10.270af00051dbc9f
5.154.75.15.221717ab4d0614e
6.14.76.1.188f1f2252da52c
6.64.76.6.157f65f45dfa1e6
6.124.76.12.110be1478849e1a
6.184.76.18.52af073bd24518
7.24.77.2.6bd02d644bd19
mainline4.77.3-rc1b38f98e17605