PT-2026-106695 · Linux · Linux
CVE-2026-98366
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: validate access flags before swapping the MR's PD
rxe rereg user mr() reassigns mr->ibmr.pd first and only then
validates the IB MR REREG ACCESS argument:
if (flags & IB MR REREG PD) {
rxe put(old pd);
rxe get(pd);
mr->ibmr.pd = ibpd;
}
if (flags & IB MR REREG ACCESS) {
if (access & ~RXE ACCESS SUPPORTED MR)
return ERR PTR(-EOPNOTSUPP);
mr->access = access;
}Both flags pass the entry check because RXE MR REREG SUPPORTED is
IB MR REREG PD | IB MR REREG ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib uverbs rereg mr() jumps to put new uobj on a driver error
without undoing the reassignment, so mr->pd == new pd while the usecnts
still charge the MR to orig pd. ib dereg mr user() then decrements
new pd, whose count can reach zero while a memory window still references
it; uverbs free pd() frees the PD on that count alone and rxe mw cleanup()
writes to freed memory:
BUG: KASAN: slab-use-after-free in rxe put+0x31/0xa0
Write of size 4 at addr ffff8881301dd690 by task rxe poc/591
rxe put+0x31/0xa0
rxe mw cleanup+0x42/0x200
rxe cleanup+0x115/0x370
rxe dealloc mw+0x4c/0x80
Allocated by task 591:
ib uverbs alloc pd+0x258/0x540
Freed by task 591:
ib dealloc pd user+0x174/0x210
uverbs free pd+0x8d/0xc0
ib uverbs dealloc pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux