PT-2026-106695 · Linux · Linux

CVE-2026-98366

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: validate access flags before swapping the MR's PD
rxe rereg user mr() reassigns mr->ibmr.pd first and only then validates the IB MR REREG ACCESS argument:
if (flags & IB MR REREG PD) {
	rxe put(old pd);
	rxe get(pd);
	mr->ibmr.pd = ibpd;
}

if (flags & IB MR REREG ACCESS) {
	if (access & ~RXE ACCESS SUPPORTED MR)
		return ERR PTR(-EOPNOTSUPP);
	mr->access = access;
}
Both flags pass the entry check because RXE MR REREG SUPPORTED is IB MR REREG PD | IB MR REREG ACCESS, so a caller can reach the access check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the success path: ib uverbs rereg mr() jumps to put new uobj on a driver error without undoing the reassignment, so mr->pd == new pd while the usecnts still charge the MR to orig pd. ib dereg mr user() then decrements new pd, whose count can reach zero while a memory window still references it; uverbs free pd() frees the PD on that count alone and rxe mw cleanup() writes to freed memory:
BUG: KASAN: slab-use-after-free in rxe put+0x31/0xa0 Write of size 4 at addr ffff8881301dd690 by task rxe poc/591 rxe put+0x31/0xa0 rxe mw cleanup+0x42/0x200 rxe cleanup+0x115/0x370 rxe dealloc mw+0x4c/0x80 Allocated by task 591: ib uverbs alloc pd+0x258/0x540 Freed by task 591: ib dealloc pd user+0x174/0x210 uverbs free pd+0x8d/0xc0 ib uverbs dealloc pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either applies every requested change or none.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98366

Affected Products

Linux