PT-2026-106696 · Linux · Linux
CVE-2026-98367
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Clear association under lock if siw qp modify fails in siw accept
We need to clear cep before release state lock as siw qp llp close and
siw qp modify->siw qp llp close did.
Otherwise if siw qp modify() fails in siw accept(), the QP's state lock
is released before the error path cleanup. A concurrent ibv modify qp()
transitioning the QP to ERROR can race in this window:
siw accept() ibv modify qp(ERROR)
siw qp modify() fails
up write(&qp->state lock)
down write(&qp->state lock)
nextstate from idle():
if (qp->cep)
siw cep put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw cep get(),
all under the write lock held from the initial down write(&qp->state lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw accept() is done with it.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux