PT-2026-106696 · Linux · Linux
CVE-2026-98367
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Clear association under lock if siw qp modify fails in siw accept
We need to clear cep before release state lock as siw qp llp close and
siw qp modify->siw qp llp close did.
Otherwise if siw qp modify() fails in siw accept(), the QP's state lock
is released before the error path cleanup. A concurrent ibv modify qp()
transitioning the QP to ERROR can race in this window:
siw accept() ibv modify qp(ERROR)
siw qp modify() fails
up write(&qp->state lock)
down write(&qp->state lock)
nextstate from idle():
if (qp->cep)
siw cep put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw cep get(),
all under the write lock held from the initial down write(&qp->state lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw accept() is done with it.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux