PT-2026-106695 · Linux · Linux
CVE-2026-98366
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: validate access flags before swapping the MR's PD
rxe rereg user mr() reassigns mr->ibmr.pd first and only then
validates the IB MR REREG ACCESS argument:
if (flags & IB MR REREG PD) {
rxe put(old pd);
rxe get(pd);
mr->ibmr.pd = ibpd;
}
if (flags & IB MR REREG ACCESS) {
if (access & ~RXE ACCESS SUPPORTED MR)
return ERR PTR(-EOPNOTSUPP);
mr->access = access;
}Both flags pass the entry check because RXE MR REREG SUPPORTED is
IB MR REREG PD | IB MR REREG ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib uverbs rereg mr() jumps to put new uobj on a driver error
without undoing the reassignment, so mr->pd == new pd while the usecnts
still charge the MR to orig pd. ib dereg mr user() then decrements
new pd, whose count can reach zero while a memory window still references
it; uverbs free pd() frees the PD on that count alone and rxe mw cleanup()
writes to freed memory:
BUG: KASAN: slab-use-after-free in rxe put+0x31/0xa0
Write of size 4 at addr ffff8881301dd690 by task rxe poc/591
rxe put+0x31/0xa0
rxe mw cleanup+0x42/0x200
rxe cleanup+0x115/0x370
rxe dealloc mw+0x4c/0x80
Allocated by task 591:
ib uverbs alloc pd+0x258/0x540
Freed by task 591:
ib dealloc pd user+0x174/0x210
uverbs free pd+0x8d/0xc0
ib uverbs dealloc pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux