{"id":"CVE-2026-74334","summary":"RDMA/nldev: Fix locking when accessing mr-\u003epd","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/nldev: Fix locking when accessing mr-\u003epd\n\nSashiko points out that, due to rereg_mr, the PD is actually variable and\nall the touches in nldev are racy.\n\nUse mr-\u003edevice instead of mr-\u003epd-\u003edevice.\n\nGetting the PD restrack ID is more tricky. To avoid disturbing all the\nhappy paths, add an rdma_restrack_sync() operation which is sort of like\nflush_workqueue() or synchronize_irq(): after it returns, all the old\nnldev touches to the mr are gone and everything sees the new PD. This\nmakes it safe to reach into the PD pointer.","modified":"2026-09-18T10:11:46.354811253Z","published":"2026-08-15T05:58:26.455Z","related":["SUSE-SU-2026:23477-1","SUSE-SU-2026:23481-1","SUSE-SU-2026:23528-1","SUSE-SU-2026:23529-1","SUSE-SU-2026:4120-1","SUSE-SU-2026:4254-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74334.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/05e26f34597e9c38bb5b340d86b179b23673869f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1a132ee4e655288d9a0937ea5109a0d038431ae9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7a0cbb5721a1da81e902d73b6049f85ca8f3fc0a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/845c6b355226195dad1f26b300c4830f57034e8b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a07cba1296aaa81bf9b914486ca957aaff196247"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74334.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74334"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"da5c8507821573b8ed6e3f47e009f273493ffaf7"},{"fixed":"845c6b355226195dad1f26b300c4830f57034e8b"},{"fixed":"7a0cbb5721a1da81e902d73b6049f85ca8f3fc0a"},{"fixed":"05e26f34597e9c38bb5b340d86b179b23673869f"},{"fixed":"a07cba1296aaa81bf9b914486ca957aaff196247"},{"fixed":"1a132ee4e655288d9a0937ea5109a0d038431ae9"},{"fixed":"50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-74334.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.18.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-74334.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}