Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-100075: Linux kernel may miscount network credits after error
CVE-2026-100075 · published 3 days ago
Summary
The Linux kernel’s RDMA component can leave internal counters incorrect if a memory allocation fails during certain network operations. This miscount can cause the system to think it has fewer or more send‑queue slots than it actually does, potentially affecting network performance. Updating the kernel to the latest version fixes the counting logic and clears the stale data.
What to do
- Update debian linux to version 7.2.6-1.
- Update linux kernel to version 7.2.6.
- Update debian linux to version 6.12.111-1.
- Update linux linux to version af00051dbc9f467d4840ec709680660a3f8990fa or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | linux | linux |
< af00051dbc9f467d4840ec709680660a3f8990fa 4.7 |
| Debian:12 | debian | linux | All versions |
| Debian:14 | debian | linux |
< 7.2.6-1 Fix: upgrade to 7.2.6-1
|
| Linux | linux | kernel |
>= 6.19.0, < 7.2.6 Fix: upgrade to 7.2.6
|
| Debian:13 | debian | linux |
< 6.12.111-1 Fix: upgrade to 6.12.111-1
|
Original advisory text
RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.
References
- https://git.kernel.org/stable/c/af00051dbc9f467d4840ec709680660a3f8990fa URL
- https://git.kernel.org/stable/c/717ab4d0614e9446bf8e2de6229464499e4008d6 URL
- https://git.kernel.org/stable/c/be1478849e1abb1e12dc12e14cdbf800cc6fa99a URL
- https://git.kernel.org/stable/c/af073bd245180393bcb15d33d3990a6bdc32593a URL
- https://git.kernel.org/stable/c/bd02d644bd19a2795c018635d273d91e45d2bb95 URL
- https://git.kernel.org/stable/c/b38f98e176050850f41bb6415f3a71400056623e URL
- https://git.kernel.org/stable/c/f1f2252da52cdda912da9993f39f58783b01b38f URL
- https://git.kernel.org/stable/c/f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d URL
- https://security-tracker.debian.org/tracker/CVE-2026-100075 Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-1000... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-100075 Vendor Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Timeline
Published25 Sep 2026
Updated29 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-100075 · NVD
CVE-2026-100075 · MITRE
DEBIAN-CVE-2026-100075 · OSV
CVE-2026-100075 · OSV
Track software like this
Free during beta