← All Advisories

CVE-2026-93277

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-93277

Key Details

CVECVE-2026-93277
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Validate udata before executing commands

The destroy callbacks currently zero the udata output after tearing down

driver resources. If the userspace access fails, uverbs preserves the

uobject and allows the destroy callback to run again, even though the

driver resource has already been freed.

Call ib_no_udata_io() before teardown so udata failures are detected

while the resource is still intact, then return success after teardown

completes.

As part of this change, move ib_respond_empty_udata() to the start of

the create and modify flows. While this is not strictly required for

general create flows, as the core layer unwinds uobjects on failure, it

is necessary for create AH. In _rdma_create_ah(), the HW object is

otherwise leaked. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93277
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93277