CVE-2026-68417

Source
https://cve.org/CVERecord?id=CVE-2026-68417
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68417.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68417
Downstream
Published
2026-08-10T12:04:37.936Z
Modified
2026-08-12T03:33:56.057392044Z
Summary
RDMA/siw: publish QP after initialization
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: publish QP after initialization

siwcreateqp() currently calls siwqpadd() before the queues, CQ pointers, state, completion, and device list entry are ready. A QPN lookup can therefore reach a QP that is still being constructed.

Move siwqpadd() to the end of siwcreateqp(), after QP initialization and before adding the QP to the siw device list.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68417.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f29dd55b0236f7a26a4b9dd69186e3c04266797b
Fixed
36e91a58397ca8c978e38a0bf389f0c6113fa8ca
Fixed
74912ad168f87d6b2b670a87987bb302d6e64aa1
Fixed
fcc9d50022bcdb1f9f7ed04955c72b4a7355af3d
Fixed
52f9fcb191143448df55fd215ff09c5207fed43e
Fixed
bb27fcc67c429d97f785c92c35a6c5adebb05d7f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68417.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68417.json"