---
id: CVE-2026-74334
title: 'RDMA/nldev: Fix locking when accessing mr->pd'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/nldev: Fix locking when accessing mr->pd

  Sashiko points out that, due to rereg_mr, the PD is actually variable and
  all the touches in nldev are racy.

  Use mr->dev…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    845c6b355226195dad1f26b300c4830f57034e8b
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    7a0cbb5721a1da81e902d73b6049f85ca8f3fc0a
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    05e26f34597e9c38bb5b340d86b179b23673869f
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    a07cba1296aaa81bf9b914486ca957aaff196247
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    1a132ee4e655288d9a0937ea5109a0d038431ae9
  - >-
    Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 <
    50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3
  - Linux 4.18
published: '2026-08-15'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:43.928Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-74334'
references:
  - url: 'https://git.kernel.org/stable/c/845c6b355226195dad1f26b300c4830f57034e8b'
  - url: 'https://git.kernel.org/stable/c/7a0cbb5721a1da81e902d73b6049f85ca8f3fc0a'
  - url: 'https://git.kernel.org/stable/c/05e26f34597e9c38bb5b340d86b179b23673869f'
  - url: 'https://git.kernel.org/stable/c/a07cba1296aaa81bf9b914486ca957aaff196247'
  - url: 'https://git.kernel.org/stable/c/1a132ee4e655288d9a0937ea5109a0d038431ae9'
  - url: 'https://git.kernel.org/stable/c/50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3'
tags:
  - cve.org
epss: 0.00129
epssPercentile: 0.0293
ingestedAt: '2026-09-14T15:23:07.456Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/nldev: Fix locking when accessing mr->pd

Sashiko points out that, due to rereg_mr, the PD is actually variable and
all the touches in nldev are racy.

Use mr->device instead of mr->pd->device.

Getting the PD restrack ID is more tricky. To avoid disturbing all the
happy paths, add an rdma_restrack_sync() operation which is sort of like
flush_workqueue() or synchronize_irq(): after it returns, all the old
nldev touches to the mr are gone and everything sees the new PD. This
makes it safe to reach into the PD pointer.

## Affected

- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < 845c6b355226195dad1f26b300c4830f57034e8b`
- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < 7a0cbb5721a1da81e902d73b6049f85ca8f3fc0a`
- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < 05e26f34597e9c38bb5b340d86b179b23673869f`
- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < a07cba1296aaa81bf9b914486ca957aaff196247`
- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < 1a132ee4e655288d9a0937ea5109a0d038431ae9`
- `Linux >= da5c8507821573b8ed6e3f47e009f273493ffaf7 < 50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3`
- `Linux 4.18`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
