{"id":"AZL-102408","summary":"CVE-2026-92488 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: complete object teardown when the destroy command fails\n\nerdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and\nerdma_destroy_ah() returned early when erdma_post_cmd_wait() failed,\nleaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN\nidentifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and\npermanently disables the command queue, so no retry can succeed; the RDMA\ncore keeps the object after a failed destructor and forced uverbs cleanup\nthen nulls the pointers, making the resources unreachable.\n\nWarn on failure but release every software-owned resource and return\nsuccess, since during terminal destruction the hardware command result is\nonly diagnostic.","modified":"2026-09-18T14:15:35.638911858Z","published":"2026-09-17T17:17:50Z","upstream":["CVE-2026-92488"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92488"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102408.json"}}],"schema_version":"1.9.0"}