PT-2026-106683 · Linux · Linux
CVE-2026-98354
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
ib mad complete recv() initializes mad recv wc->rmpp list and then runs
ib mad enforce security() before linking recv buf onto that list. On
failure it calls ib free recv mad(), which only walks rmpp list and frees
the ib mad private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib mad recv done() sets recv to NULL
right after ib mad complete recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib mad private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv buf onto rmpp list right after the list is initialized, so the
error path has something to free.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux