PatchSiren cyber security CVE debrief
CVE-2026-46117 Linux CVE debrief
A vulnerability in the Linux kernel's RDMA/mana driver allowed user-space applications to trigger a WARN_ON() assertion and subsequent kernel memory corruption. The flaw existed in the mana_ib_create_qp_rss() function, where user-controlled input specifying Work Queues (WQs) sharing the same Completion Queue (CQ) would trigger a warning condition that the code then proceeded past, leading to corruption. The fix replaces the WARN_ON() with an explicit rejection that fails QP creation safely.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-30
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-30
Who should care
Organizations running Linux systems with Microsoft Azure Network Adapter (MANA) RDMA hardware, cloud providers offering RDMA-enabled instances, and enterprises using high-performance computing workloads that rely on kernel RDMA subsystems.
Technical summary
The RDMA/mana driver in the Linux kernel contained a vulnerability in mana_ib_create_qp_rss() where user-space could specify Work Queues sharing the same Completion Queue. This configuration triggered a WARN_ON() assertion that, rather than halting execution, was followed by code that corrupted kernel memory. The vulnerability is user-triggerable through the RDMA uAPI. The resolution removes the WARN_ON() and replaces it with proper validation that rejects the invalid QP configuration, preventing the corruption path.
Defensive priority
medium
Recommended defensive actions
- Apply kernel updates containing the fix commits for affected stable branches
- Review systems using Microsoft Azure Network Adapter (MANA) RDMA functionality for kernel stability issues
- Monitor kernel logs for QP creation failures in RDMA/mana after patching
- Validate RDMA application configurations avoid WQ/CQ sharing patterns that previously triggered this condition
Evidence notes
The vulnerability description indicates this was a user-triggerable kernel corruption path in RDMA/mana driver QP creation. The fix commit removes the WARN_ON() and adds proper validation to reject invalid WQ/CQ configurations. Multiple stable kernel branches received backports.
Official resources
-
CVE-2026-46117 CVE record
CVE.org
-
CVE-2026-46117 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
2026-05-28