CVE Database
/

CVE-2026-46181

Back to search

CVE-2026-46181

Published: May 28, 2026

Modified: May 30, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() Sashiko points out the radix_tree itself is RCU safe, but nothing ever frees the mlx4_srq struct with RCU, and it isn't even accessed within the RCU critical section. It also will crash if an event is delivered before the srq object is finished initializing. Use the spinlock since it isn't easy to make RCU work, use refcount_inc_not_zero() to protect against partially initialized objects, and order the refcount_set() to be after the srq is fully initialized.

VendorProductVersions

Linux

Linux

affected
30353bfc43a1602c020f31d95cf27182ffd23824 - < 1e2a44875b6afb4add1115f7f3351dcbeb6f273d
affected
30353bfc43a1602c020f31d95cf27182ffd23824 - < 8b7833f3bce35cb0d01c1503781523c099c675f0
affected
30353bfc43a1602c020f31d95cf27182ffd23824 - < c9341307ea16b9395c2e4c9c94d8499d91fe31d0

Linux

Linux

affected
4.9
unaffected
0 - < 4.9
unaffected
6.18.30 - <= 6.18.*
unaffected
7.0.7 - <= 7.0.*
unaffected
7.1-rc3 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now