Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90308NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Hold QP references for AE and CM processing

AE QP fatal events and iWARP CM paths load QPs from dev->qp_xa
and then use or reference them outside the xarray lock.
erdma_destroy_qp() can drop the destroy-path reference and free QP
resources while such a lookup is in flight.

Add erdma_qp_get_by_qpn() to acquire a kref under the xarray
lock with kref_get_unless_zero(). Remove the QP from the xarray
before dropping the destroy-path reference so no new lookup can acquire
it while destruction waits for existing users.
Severity Level
HIGH(7.8)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.16%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 155055771704f8cbb5c176a4309b7dc30a50450c and < 6e32f84b63c054e09392153125d7202abab2d14b
  • Linux Linux >= 155055771704f8cbb5c176a4309b7dc30a50450c and < ec987c0654651036dad6a42f7fa2a6d7c16a3687
  • Linux Linux >= 155055771704f8cbb5c176a4309b7dc30a50450c and < c92686867638cda954fdb2bdbac8a75e3aa6eaae
  • Linux Linux >= 155055771704f8cbb5c176a4309b7dc30a50450c and < a52eeff32024f190b3bdc99088c7becccd4fa60b
  • Linux Linux >= 6.0
Patched Versions
  • Linux Linux 6e32f84b63c054e09392153125d7202abab2d14b
  • Linux Linux ec987c0654651036dad6a42f7fa2a6d7c16a3687
  • Linux Linux c92686867638cda954fdb2bdbac8a75e3aa6eaae
  • Linux Linux a52eeff32024f190b3bdc99088c7becccd4fa60b
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.