PT-2026-106582 · Linux · Linux
CVE-2026-98253
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/ucma: Serialize join and leave on copy to user failure
rdma join multicast() queues RoCE work that later reads the ucma multicast
through event->param.ud.private data, then list add()s the CMA multicast
at the head of id priv->mc list. rdma leave multicast() matches only by
sockaddr and destroys the first hit.
ucma process join() used to drop ctx->mutex after a successful join and
retake it only if copy to user() failed. Two concurrent JOIN MCAST calls
with the same address can therefore insert a second CMA entry before the
first thread's leave. leave then cancels the newer work and the older
worker still dereferences the ucma multicast that the first thread frees.
Keep ctx->mutex held from rdma join multicast() through copy to user() and,
on -EFAULT, through rdma leave multicast() so leave cannot miss this join.
Do not leave if join itself failed: that path never published this address
on mc list, and a leave-by-addr would destroy an earlier successful join.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux