{"id":"CVE-2026-64582","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's k…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's k…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","published":"2026-08-05","updated":"2026-08-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64582","references":[{"url":"https://git.kernel.org/stable/c/3525987a392536f31a484833af258971af63b24c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35744ab3d03c5fca8c1752f53fc8fc674e14c561","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/665fb7d22a700c66a78db0cf88c6e6a649aba9d0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e038d42cc09ca1da9d3568ce8ae062b2bfb3bc0e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e59a6aa89e0fcd1d0707832eb4654fd9ae7d31e6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64582.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-64582"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511448"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64582"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64582"},{"url":"https://lore.kernel.org/linux-cve-announce/2026080518-CVE-2026-64582-9922@gregkh/T"},{"url":"https://access.redhat.com/errata/RHSA-2026:68570"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0013,"epssPercentile":0.02988,"ingestedAt":"2026-08-08T21:30:13.037Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 7","enterprise_linux 8","enterprise_linux 9"],"cwe":["CWE-825"],"patched":["enterprise_linux_appstream_v_9","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_v_9","enterprise_linux_real_time_for_nfv_v_9","enterprise_linux_real_time_v_9"],"slug":"CVE-2026-64582","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix a use-after-free problem in rxe_mmap\n\nrxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list\nand releases pending_lock while the struct's kref is still at 1:\n\n   list_del_init(&ip->pending_mmaps);\n   spin_unlock_bh(&rxe->pending_lock);   /* ref == 1, no lock held */\n   ret = remap_vmalloc_range(vma, ip->obj, 0);  /* walks PTEs */\n   [...]\n   rxe_vma_open(vma);                    /* kref_get, ref → 2 */\n   remap_vmalloc_range_partial() walks PTEs without any lock.\n\nA concurrent DESTROY_CQ ioctl on another CPU calls:\n\n    kref_put(&q->ip->ref, rxe_mmap_release)   /* ref 1→0 */\n    vfree(ip->obj)   /* clears vmalloc PTEs mid-walk */\n    kfree(ip)        /* frees rxe_mmap_info */\n\nThis yields:\n\n   1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the\n   per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert\n\n   2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears\n   it. User VMA holds a PTE to a free'd page which might eventually get\n   reallocated later by vmalloc which allows the attacker to get a clean\n   page-level UAF.\n\n   It is worth noting that even though a page-level UAF is possible given\n   the strong primitive, it is statistically very difficult to achieve\n   given the very short time window (after the last insert_page and before\n   the kref_get).\n\nThe call trace are as below:\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n  CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy)\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n  RIP: 0010:validate_page_before_insert+0x32/0x300\n  Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5\n  RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\n  RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008\n  RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00\n  R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20\n  FS:  00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0\n  Call Trace:\n   <TASK>\n   insert_page+0x8f/0x190\n   ? __pfx_insert_page+0x10/0x10\n   ? kasan_save_alloc_info+0x38/0x60\n   vm_insert_page+0x2e7/0x400\n   remap_vmalloc_range_partial+0x212/0x3e0\n   remap_vmalloc_range+0x6e/0xb0\n   ? __kasan_check_write+0x14/0x30\n   rxe_mmap+0x2e9/0x5d0\n   ib_uverbs_mmap+0x1ad/0x2c0\n   __mmap_region+0x12c2/0x2ad0\n   ? __pfx___mmap_region+0x10/0x10\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_prev_slot+0x360/0x39c0\n   ? __sanitizer_cov_trace_switch+0x58/0xb0\n   ? mas_next_slot+0x1e5b/0x2f40\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   ? unmapped_area_topdown+0x4dd/0x610\n   ? kfree+0x1b1/0x440\n   ? free_cpumask_var+0x16/0x30\n   ? __kasan_slab_free+0x7d/0xa0\n   ? __sanitizer_cov_trace_cmp8+0x18/0x30\n   mmap_region+0x2e6/0x3c0\n   do_mmap+0xa3e/0x12a0\n   ? __pfx_do_mmap+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? down_write_killable+0xba/0x160\n   ? __pfx_down_write_killable+0x10/0x10\n   ? __sanitizer_cov_trace_cmp4+0x16/0x30\n   vm_mmap_pgoff+0x2d4/0x4a0\n   ? __pfx_vm_mmap_pgoff+0x10/0x10\n   ? fget+0x1bf/0x270\n   ksys_mmap_pgoff+0x40c/0x690\n   ? __sanitizer_cov_trace_const_cmp4+0x16/0x30\n   ? __pfx_ksys_mmap_pgoff+0x10/0x10\n   ? __kasan_check_write+0x14/0x30\n   ? _raw_spin_trylock+0xbb/0x130\n   ? __pfx__raw_spin_trylock+0x10/0x10\n   __x64_sys_mmap+0x135/0x1e0\n   x64_sys_c\n---truncated---\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-64582.json)\n- **RHSA-2026:68570** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68570)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}