PT-2026-106696 · Linux · Linux

CVE-2026-98367

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Clear association under lock if siw qp modify fails in siw accept
We need to clear cep before release state lock as siw qp llp close and siw qp modify->siw qp llp close did.
Otherwise if siw qp modify() fails in siw accept(), the QP's state lock is released before the error path cleanup. A concurrent ibv modify qp() transitioning the QP to ERROR can race in this window:
siw accept() ibv modify qp(ERROR)

siw qp modify() fails up write(&qp->state lock) down write(&qp->state lock) nextstate from idle(): if (qp->cep) siw cep put(qp->cep) <- frees cep qp->cep = NULL goto error cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw cep get(), all under the write lock held from the initial down write(&qp->state lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw accept() is done with it.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98367

Produtos afetados

Linux