{"id":"CVE-2026-100075","summary":"RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA contexts but leaves stale\nn_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later\nsq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()\ncan then subtract the wrong number of send queue credits.\n\nReset the counters and clear rw_ctxs after freeing the heap\nallocation before returning an error.","modified":"2026-09-27T03:46:17.739583370Z","published":"2026-09-25T13:06:47.399Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100075.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/717ab4d0614e9446bf8e2de6229464499e4008d6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af00051dbc9f467d4840ec709680660a3f8990fa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af073bd245180393bcb15d33d3990a6bdc32593a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b38f98e176050850f41bb6415f3a71400056623e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bd02d644bd19a2795c018635d273d91e45d2bb95"},{"type":"WEB","url":"https://git.kernel.org/stable/c/be1478849e1abb1e12dc12e14cdbf800cc6fa99a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f1f2252da52cdda912da9993f39f58783b01b38f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100075.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100075"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"b99f8e4d7bcd3bfbb3cd965918523299370d0cb2"},{"fixed":"af00051dbc9f467d4840ec709680660a3f8990fa"},{"fixed":"717ab4d0614e9446bf8e2de6229464499e4008d6"},{"fixed":"f1f2252da52cdda912da9993f39f58783b01b38f"},{"fixed":"f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d"},{"fixed":"be1478849e1abb1e12dc12e14cdbf800cc6fa99a"},{"fixed":"af073bd245180393bcb15d33d3990a6bdc32593a"},{"fixed":"bd02d644bd19a2795c018635d273d91e45d2bb95"},{"fixed":"b38f98e176050850f41bb6415f3a71400056623e"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100075.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100075.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}