PT-2026-106683 · Linux · Linux
CVE-2026-98354
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
ib mad complete recv() initializes mad recv wc->rmpp list and then runs
ib mad enforce security() before linking recv buf onto that list. On
failure it calls ib free recv mad(), which only walks rmpp list and frees
the ib mad private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib mad recv done() sets recv to NULL
right after ib mad complete recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib mad private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv buf onto rmpp list right after the list is initialized, so the
error path has something to free.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux