{"id":"AZL-96543","summary":"CVE-2026-72469 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix ep kref imbalance on ADDR_CHANGE\n\nrpcrdma_cm_event_handler() falls through to the disconnected: label\non RDMA_CM_EVENT_ADDR_CHANGE and calls rpcrdma_ep_put() with no\nmatching get when the event arrives before RDMA_CM_EVENT_ESTABLISHED.\nThe kref then underflows during connect teardown and\nrpcrdma_xprt_disconnect() operates on a freed ep.\n\nReference counts across a normal connection lifecycle:\n\n    rpcrdma_ep_create()             kref_init     -\u003e1\n    rpcrdma_xprt_connect()          ep_get        -\u003e2  (before post_recvs)\n    RDMA_CM_EVENT_ESTABLISHED       ep_get        -\u003e3\n    RDMA_CM_EVENT_DISCONNECTED      ep_put        -\u003e2\n    rpcrdma_xprt_drain()            ep_put        -\u003e1\n    rpcrdma_xprt_disconnect() tail  ep_put        -\u003e0  (ep_destroy)\n\nThe connect-time get in rpcrdma_xprt_connect(), taken just before\nrpcrdma_post_recvs() \"while there are outstanding Receives,\" is\nbalanced by rpcrdma_xprt_drain. ADDR_CHANGE before ESTABLISHED has\nno get to consume, so its put drops the count to 1 and the drain\nput then frees the ep while rpcrdma_xprt_disconnect() still holds a\npointer to it.\n\nFix by dispatching on the prior re_connect_status via xchg(): for\nprev == 0 (pre-ESTABLISHED) wake the connect waiter and return with\nno put; for prev == 1 call rpcrdma_force_disconnect() and return.\nThe case-1 arm relies on the subsequent RDMA_CM_EVENT_DISCONNECTED\nevent -- reliably delivered when rdma_disconnect() is called on a\nstill-connected cm_id -- to balance the ESTABLISHED get;\nrpcrdma_xprt_drain() continues to balance only that connect-time\nget. Any other prior value means teardown is already in flight.","modified":"2026-08-31T05:26:27Z","published":"2026-08-15T06:22:20Z","upstream":["CVE-2026-72469"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72469"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96543.json"}}],"schema_version":"1.9.0"}