---
id: CVE-2026-45852
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/rxe: Fix double free in rxe_srq_from_init

  In rxe_srq_from_init(), the queue pointer 'q' is assigned to
  'srq->rq.queue' before copying the SRQ number to user space…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/rxe: Fix double free in rxe_srq_from_init

  In rxe_srq_from_init(), the queue pointer 'q' is assigned to
  'srq->rq.queue' before copying the SRQ number to user space…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-415
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.19.86, < 5.10.259'
  - 'linux_kernel >= 5.11, < 5.15.210'
  - 'linux_kernel >= 5.16, < 6.1.176'
  - 'linux_kernel >= 6.2, < 6.6.128'
  - 'linux_kernel >= 6.7, < 6.12.75'
  - 'linux_kernel >= 6.13, < 6.18.14'
  - 'linux_kernel >= 6.19, < 6.19.4'
patched:
  - linux_kernel 6.19.4
published: '2026-05-27'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45852'
references:
  - url: 'https://git.kernel.org/stable/c/0beefd0e15d962f497aad750b2d5e9c3570b66d1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/26793db60925df1e88a29466813d586cbc190b8c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/26a9cfe12f4ffdeaa136f252478986fa5f397ddc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5c07aef09a121a4cd622a71eb0753a9e135c84a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9abff51163aa1bc275ec356f74fe976291860a7f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b98ab5494dbd48652561aa0b9c32f10500220745'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce6f8e007682f378279d4cf83b240f12d52c723b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d493e0bfc748a520c349d6c8791b262aa5ad2e4e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://access.redhat.com/errata/RHSA-2026:25120'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25121'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25217'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27713'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:33899'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34094'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-45852'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482166'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45852.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.07291
ingestedAt: '2026-07-02T13:35:59.421Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix double free in rxe_srq_from_init

In rxe_srq_from_init(), the queue pointer 'q' is assigned to
'srq->rq.queue' before copying the SRQ number to user space.
If copy_to_user() fails, the function calls rxe_queue_cleanup()
to free the queue, but leaves the now-invalid pointer in
'srq->rq.queue'.

The caller of rxe_srq_from_init() (rxe_create_srq) eventually
calls rxe_srq_cleanup() upon receiving the error, which triggers
a second rxe_queue_cleanup() on the same memory, leading to a
double free.

The call trace looks like this:
   kmem_cache_free+0x.../0x...
   rxe_queue_cleanup+0x1a/0x30 [rdma_rxe]
   rxe_srq_cleanup+0x42/0x60 [rdma_rxe]
   rxe_elem_release+0x31/0x70 [rdma_rxe]
   rxe_create_srq+0x12b/0x1a0 [rdma_rxe]
   ib_create_srq_user+0x9a/0x150 [ib_core]

Fix this by moving 'srq->rq.queue = q' after copy_to_user.

## Affected

- `linux_kernel >= 4.19.86, < 5.10.259`
- `linux_kernel >= 5.11, < 5.15.210`
- `linux_kernel >= 5.16, < 6.1.176`
- `linux_kernel >= 6.2, < 6.6.128`
- `linux_kernel >= 6.7, < 6.12.75`
- `linux_kernel >= 6.13, < 6.18.14`
- `linux_kernel >= 6.19, < 6.19.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.4`
