In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the… (CVE-2026-93037)
A vulnerability in the Linux kernel's RDMA/hfi1 component was resolved where the function set_txreq_header_ahg() ignored errors from sdma_txinit_ahg(). This caused request processing to continue despite initialization failures, potentially leading to high impact on confidentiality, integrity, and availability. The issue has been fixed by propagating errors properly and aborting request processing on failure.
AI Analysis
Technical Summary
The Linux kernel RDMA/hfi1 subsystem had a vulnerability (CVE-2026-93037) where set_txreq_header_ahg() did not check the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() failed, tx->txreq was not initialized, but set_txreq_header_ahg() still returned the AHG change count, misleading the caller to proceed as if initialization succeeded. The fix propagates sdma_txinit_ahg() errors to the caller and aborts processing when initialization fails. This vulnerability was discovered by the Linux Verification Center using SVACE.
Potential Impact
Because the function ignored initialization errors, the system could process requests with uninitialized data structures, potentially leading to severe impacts on confidentiality, integrity, and availability of the affected system. The CVSS score of 7.8 reflects a high severity with local attack vector, low complexity, and no user interaction required.
Mitigation Recommendations
A fix has been applied to the Linux kernel to propagate errors from sdma_txinit_ahg() and abort request processing on failure. Users should update to the fixed kernel versions once available. Patch status is not explicitly confirmed in the provided data; check the official Linux kernel advisories for the exact fixed versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the… (CVE-2026-93037)
Description
A vulnerability in the Linux kernel's RDMA/hfi1 component was resolved where the function set_txreq_header_ahg() ignored errors from sdma_txinit_ahg(). This caused request processing to continue despite initialization failures, potentially leading to high impact on confidentiality, integrity, and availability. The issue has been fixed by propagating errors properly and aborting request processing on failure.
CVSS v3.1
Score 7.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel RDMA/hfi1 subsystem had a vulnerability (CVE-2026-93037) where set_txreq_header_ahg() did not check the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() failed, tx->txreq was not initialized, but set_txreq_header_ahg() still returned the AHG change count, misleading the caller to proceed as if initialization succeeded. The fix propagates sdma_txinit_ahg() errors to the caller and aborts processing when initialization fails. This vulnerability was discovered by the Linux Verification Center using SVACE.
Potential Impact
Because the function ignored initialization errors, the system could process requests with uninitialized data structures, potentially leading to severe impacts on confidentiality, integrity, and availability of the affected system. The CVSS score of 7.8 reflects a high severity with local attack vector, low complexity, and no user interaction required.
Mitigation Recommendations
A fix has been applied to the Linux kernel to propagate errors from sdma_txinit_ahg() and abort request processing on failure. Users should update to the fixed kernel versions once available. Patch status is not explicitly confirmed in the provided data; check the official Linux kernel advisories for the exact fixed versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rqc6-x86p-g5jv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-93037"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aade51855bf5e2cf5edc038
Added to database: 09/19/2026, 01:27:52 UTC
Last enriched: 09/19/2026, 01:44:03 UTC
Last updated: 09/19/2026, 03:04:43 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.