Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-100075: Linux kernel may miscount network credits after error

CVE-2026-100075 · published 3 days ago
Summary

The Linux kernel’s RDMA component can leave internal counters incorrect if a memory allocation fails during certain network operations. This miscount can cause the system to think it has fewer or more send‑queue slots than it actually does, potentially affecting network performance. Updating the kernel to the latest version fixes the counting logic and clears the stale data.

What to do
  • Update debian linux to version 7.2.6-1.
  • Update linux kernel to version 7.2.6.
  • Update debian linux to version 6.12.111-1.
  • Update linux linux to version af00051dbc9f467d4840ec709680660a3f8990fa or later.
Affected software
Ecosystem VendorProductAffected versions
– linux linux < af00051dbc9f467d4840ec709680660a3f8990fa
4.7
Debian:12 debian linux All versions
Debian:14 debian linux < 7.2.6-1
Fix: upgrade to 7.2.6-1
Linux linux kernel >= 6.19.0, < 7.2.6
Fix: upgrade to 7.2.6
Debian:13 debian linux < 6.12.111-1
Fix: upgrade to 6.12.111-1
Original advisory text
RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending() can then subtract the wrong number of send queue credits. Reset the counters and clear rw_ctxs after freeing the heap allocation before returning an error.
Severity
9.8 Critical
Exploitation
EPSS <1%
Timeline
Published25 Sep 2026
Updated29 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta