{"id":"CVE-2026-100075","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA c…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA c…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < af00051dbc9f467d4840ec709680660a3f8990fa","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < 717ab4d0614e9446bf8e2de6229464499e4008d6","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < f1f2252da52cdda912da9993f39f58783b01b38f","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < be1478849e1abb1e12dc12e14cdbf800cc6fa99a","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < af073bd245180393bcb15d33d3990a6bdc32593a","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < bd02d644bd19a2795c018635d273d91e45d2bb95","Linux >= b99f8e4d7bcd3bfbb3cd965918523299370d0cb2 < b38f98e176050850f41bb6415f3a71400056623e","Linux 4.7"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T15:17:52.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100075","references":[{"url":"https://git.kernel.org/stable/c/717ab4d0614e9446bf8e2de6229464499e4008d6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af00051dbc9f467d4840ec709680660a3f8990fa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af073bd245180393bcb15d33d3990a6bdc32593a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b38f98e176050850f41bb6415f3a71400056623e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd02d644bd19a2795c018635d273d91e45d2bb95","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be1478849e1abb1e12dc12e14cdbf800cc6fa99a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1f2252da52cdda912da9993f39f58783b01b38f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f65f45dfa1e6e2eaa9e11c8b8ce8857799cb189d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T14:09:46.376Z","slug":"CVE-2026-100075","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA contexts but leaves stale\nn_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later\nsq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()\ncan then subtract the wrong number of send queue credits.\n\nReset the counters and clear rw_ctxs after freeing the heap\nallocation before returning an error.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210883,"id":"CVE-2026-100075","ts":1790349106002,"field":"cvss","old":null,"new":"9.8"},{"seq":210882,"id":"CVE-2026-100075","ts":1790349106002,"field":"severity","old":"none","new":"critical"}]}