← All Advisories

CVE-2026-98366

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98366

Key Details

CVECVE-2026-98366
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: validate access flags before swapping the MR's PD

rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then

validates the IB_MR_REREG_ACCESS argument:

if (flags & IB_MR_REREG_PD) {

rxe_put(old_pd);

rxe_get(pd);

mr->ibmr.pd = ibpd;

}

if (flags & IB_MR_REREG_ACCESS) {

if (access & ~RXE_ACCESS_SUPPORTED_MR)

return ERR_PTR(-EOPNOTSUPP);

mr->access = access;

}

Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is

IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access

check with mr->ibmr.pd already reassigned.

mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the

success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error

without undoing the reassignment, so mr->pd == new_pd while the usecnts

still charge the MR to orig_pd. ib_dereg_mr_user() then decrements

new_pd, whose count can reach zero while a memory window still references

it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup()

writes to freed memory:

BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0

Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591

__rxe_put+0x31/0xa0

rxe_mw_cleanup+0x42/0x200

__rxe_cleanup+0x115/0x370

rxe_dealloc_mw+0x4c/0x80

Allocated by task 591:

ib_uverbs_alloc_pd+0x258/0x540

Freed by task 591:

ib_dealloc_pd_user+0x174/0x210

uverbs_free_pd+0x8d/0xc0

ib_uverbs_dealloc_pd+0x18e/0x1d0

Validate the access flags before mutating any state so the callback either

applies every requested change or none. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98366
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98366