CVE-2026-98252

Source
https://cve.org/CVERecord?id=CVE-2026-98252
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98252.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98252
Downstream
Published
2026-10-06T08:45:19Z
Modified
2026-10-08T02:52:55Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

iwpm_get_nlmsg_request() initializes refcount after list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref before list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98252.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30dc5e63d6a5ad24894b5512d10b228d73645a44
Fixed
52c13c63bb3662c108244e7447055e30bf40244e
Fixed
8a91609032d47e77bcb37bc8f6e88d89340d2709
Fixed
ce8a379598bd4058081416abea4279fd05a95374
Fixed
2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8
Fixed
88e429a4e9bac3d2138011c5ca06254331f2587f
Fixed
e15eb536be4f646ce683d2867572b2200be877f7
Fixed
117871cdb8927542abd7b65ce5995bf0265a8c05
Fixed
33fb59da49c4c3f5c2ec9f9d4447a56857a02c02

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98252.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.16.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98252.json"