PT-2026-106683 · Linux · Linux

CVE-2026-98354

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
ib mad complete recv() initializes mad recv wc->rmpp list and then runs ib mad enforce security() before linking recv buf onto that list. On failure it calls ib free recv mad(), which only walks rmpp list and frees the ib mad private of every buffer found there. As the list is still empty at that point, nothing is freed at all.
The caller cannot clean up either: ib mad recv done() sets recv to NULL right after ib mad complete recv() returns, assuming the MAD layer took ownership of the buffer. Every MAD that fails the PKey check therefore leaks one ib mad private (about 300 bytes per IB port MAD, ~2K for OPA), and a remote node can trigger this repeatedly by sending MADs with a wrong PKey.
Link recv buf onto rmpp list right after the list is initialized, so the error path has something to free.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98354

Affected Products

Linux