PT-2026-106582 · Linux · Linux

CVE-2026-98253

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/ucma: Serialize join and leave on copy to user failure
rdma join multicast() queues RoCE work that later reads the ucma multicast through event->param.ud.private data, then list add()s the CMA multicast at the head of id priv->mc list. rdma leave multicast() matches only by sockaddr and destroys the first hit.
ucma process join() used to drop ctx->mutex after a successful join and retake it only if copy to user() failed. Two concurrent JOIN MCAST calls with the same address can therefore insert a second CMA entry before the first thread's leave. leave then cancels the newer work and the older worker still dereferences the ucma multicast that the first thread frees.
Keep ctx->mutex held from rdma join multicast() through copy to user() and, on -EFAULT, through rdma leave multicast() so leave cannot miss this join. Do not leave if join itself failed: that path never published this address on mc list, and a leave-by-addr would destroy an earlier successful join.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98253

Affected Products

Linux