{"schema_version":"1.7.5","id":"CVE-2026-43120","published":"2026-05-06T07:40:43.923Z","modified":"2026-07-28T18:30:24.607099128Z","related":["CGA-xx5q-6p5h-qv56","SUSE-SU-2026:21876-1","SUSE-SU-2026:21877-1","SUSE-SU-2026:21916-1","SUSE-SU-2026:21919-1","SUSE-SU-2026:2195-1","SUSE-SU-2026:2217-1","SUSE-SU-2026:2238-1","SUSE-SU-2026:22598-1","SUSE-SU-2026:22673-1","SUSE-SU-2026:22674-1","SUSE-SU-2026:22675-1","SUSE-SU-2026:22676-1","SUSE-SU-2026:22677-1","SUSE-SU-2026:22678-1","SUSE-SU-2026:22680-1","SUSE-SU-2026:22681-1","SUSE-SU-2026:22682-1","SUSE-SU-2026:22683-1","SUSE-SU-2026:22684-1","SUSE-SU-2026:22685-1","SUSE-SU-2026:22686-1","SUSE-SU-2026:22687-1","SUSE-SU-2026:22689-1","SUSE-SU-2026:22690-1","SUSE-SU-2026:22691-1","SUSE-SU-2026:22692-1","SUSE-SU-2026:22693-1","SUSE-SU-2026:22694-1","SUSE-SU-2026:22695-1","SUSE-SU-2026:22696-1","SUSE-SU-2026:22697-1","SUSE-SU-2026:22711-1","SUSE-SU-2026:22712-1","SUSE-SU-2026:22713-1","SUSE-SU-2026:22714-1","SUSE-SU-2026:22715-1","SUSE-SU-2026:22716-1","SUSE-SU-2026:22717-1","SUSE-SU-2026:22718-1","SUSE-SU-2026:22719-1","SUSE-SU-2026:22720-1","SUSE-SU-2026:22721-1","SUSE-SU-2026:22722-1","SUSE-SU-2026:22723-1","SUSE-SU-2026:22725-1","SUSE-SU-2026:22726-1","SUSE-SU-2026:22728-1","SUSE-SU-2026:22729-1","SUSE-SU-2026:22730-1","SUSE-SU-2026:22731-1","SUSE-SU-2026:22732-1","SUSE-SU-2026:22733-1","SUSE-SU-2026:22734-1","SUSE-SU-2026:22735-1","SUSE-SU-2026:22743-1","SUSE-SU-2026:22744-1","SUSE-SU-2026:22746-1","SUSE-SU-2026:22747-1","SUSE-SU-2026:22748-1","SUSE-SU-2026:22749-1","SUSE-SU-2026:22755-1","SUSE-SU-2026:22758-1","SUSE-SU-2026:22759-1","SUSE-SU-2026:22761-1","SUSE-SU-2026:22762-1","SUSE-SU-2026:22763-1","SUSE-SU-2026:22775-1","SUSE-SU-2026:22776-1","SUSE-SU-2026:22777-1","SUSE-SU-2026:22778-1","SUSE-SU-2026:22780-1","SUSE-SU-2026:22781-1","SUSE-SU-2026:22782-1","SUSE-SU-2026:22783-1","SUSE-SU-2026:22784-1","SUSE-SU-2026:22785-1","SUSE-SU-2026:22786-1","SUSE-SU-2026:22792-1","SUSE-SU-2026:22793-1","SUSE-SU-2026:22794-1","SUSE-SU-2026:22795-1","SUSE-SU-2026:22864-1","SUSE-SU-2026:22865-1","SUSE-SU-2026:22867-1","SUSE-SU-2026:22868-1","SUSE-SU-2026:22869-1","SUSE-SU-2026:22870-1","SUSE-SU-2026:22872-1","SUSE-SU-2026:22873-1","SUSE-SU-2026:22874-1","SUSE-SU-2026:22875-1","SUSE-SU-2026:22876-1","SUSE-SU-2026:22877-1","SUSE-SU-2026:22912-1","SUSE-SU-2026:22913-1","SUSE-SU-2026:22914-1","SUSE-SU-2026:22915-1","SUSE-SU-2026:2855-1","SUSE-SU-2026:2857-1","SUSE-SU-2026:2858-1","SUSE-SU-2026:2866-1","SUSE-SU-2026:2887-1","SUSE-SU-2026:2894-1","SUSE-SU-2026:2895-1","SUSE-SU-2026:2902-1","SUSE-SU-2026:2930-1","SUSE-SU-2026:2943-1","SUSE-SU-2026:2945-1","SUSE-SU-2026:2956-1","SUSE-SU-2026:2957-1"],"summary":"RDMA/irdma: Fix double free related to rereg_user_mr","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix double free related to rereg_user_mr\n\nIf IB_MR_REREG_TRANS is set during rereg_user_mr, the\numem will be released and a new one will be allocated\nin irdma_rereg_mr_trans. If any step of irdma_rereg_mr_trans\nfails after the new umem is allocated, it releases the umem,\nbut does not set iwmr->region to NULL. The problem is that\nthis failure is propagated to the user, who will then call\nibv_dereg_mr (as they should). Then, the dereg_mr path will\nsee a non-NULL umem and attempt to call ib_umem_release again.\n\nFix this by setting iwmr->region to NULL after ib_umem_release.\n\nFixed: 5ac388db27c4 (\"RDMA/irdma: Add support to re-register a memory region\")","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"715fdb3b30541cc8180b7cdc6aa9f8c307afdf25"},{"fixed":"62298a48f8b8788ad8b8464e6ffdf1ddebd2217e"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5ac388db27c443dadfbb0b8b23fa7ccf429d901a"},{"fixed":"66964118f1f50ed85001c8fc9f7ab5bbdd021ee0"},{"fixed":"0f22c32141acdcda266b26cab2b830baf870f3e0"},{"fixed":"0c5d70bcb9d2275a1c8515a924016fcfeb4ab441"},{"fixed":"29a3edd7004bb635d299fb9bc6f0ea4ef13ed5a2"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.6.120"},{"fixed":"6.6.136"}]}],"versions":["v6.6.135","v6.6.134","v6.6.133","v6.6.132","v6.6.131","v6.6.130","v6.6.129","v6.6.128","v6.6.127","v6.6.126","v6.6.125","v6.6.124","v6.6.123","v6.6.122","v6.6.121","v6.6.120"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43120.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.6.136"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.83"},{"fixed":"6.18.24"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.19.14"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43120.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0c5d70bcb9d2275a1c8515a924016fcfeb4ab441"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0f22c32141acdcda266b26cab2b830baf870f3e0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/29a3edd7004bb635d299fb9bc6f0ea4ef13ed5a2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/62298a48f8b8788ad8b8464e6ffdf1ddebd2217e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/66964118f1f50ed85001c8fc9f7ab5bbdd021ee0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43120.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43120"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43120.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}