PT-2026-106695 · Linux · Linux

CVE-2026-98366

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: validate access flags before swapping the MR's PD
rxe rereg user mr() reassigns mr->ibmr.pd first and only then validates the IB MR REREG ACCESS argument:
if (flags & IB MR REREG PD) {
	rxe put(old pd);
	rxe get(pd);
	mr->ibmr.pd = ibpd;
}

if (flags & IB MR REREG ACCESS) {
	if (access & ~RXE ACCESS SUPPORTED MR)
		return ERR PTR(-EOPNOTSUPP);
	mr->access = access;
}
Both flags pass the entry check because RXE MR REREG SUPPORTED is IB MR REREG PD | IB MR REREG ACCESS, so a caller can reach the access check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the success path: ib uverbs rereg mr() jumps to put new uobj on a driver error without undoing the reassignment, so mr->pd == new pd while the usecnts still charge the MR to orig pd. ib dereg mr user() then decrements new pd, whose count can reach zero while a memory window still references it; uverbs free pd() frees the PD on that count alone and rxe mw cleanup() writes to freed memory:
BUG: KASAN: slab-use-after-free in rxe put+0x31/0xa0 Write of size 4 at addr ffff8881301dd690 by task rxe poc/591 rxe put+0x31/0xa0 rxe mw cleanup+0x42/0x200 rxe cleanup+0x115/0x370 rxe dealloc mw+0x4c/0x80 Allocated by task 591: ib uverbs alloc pd+0x258/0x540 Freed by task 591: ib dealloc pd user+0x174/0x210 uverbs free pd+0x8d/0xc0 ib uverbs dealloc pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either applies every requested change or none.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98366

Produtos afetados

Linux