ThreatCluster

Microsoft Addresses Two RDMA/iwcm Vulnerabilities in February 2026

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Microsoft has published information on two vulnerabilities affecting the RDMA/iwcm component. CVE-2025-38211, published on July 4, 2025, addresses a use-after-free issue after cm_id destruction, while CVE-2024-47696, published on October 21, 2024, resolves a warning related to workqueue dependencies. Both vulnerabilities could impact systems utilizing RDMA technology.

Timeline

2024-10-21
CVE-2024-47696 published
2025-07-04
CVE-2025-38211 published
2026-02-18
Microsoft publishes information on both vulnerabilities