CVE-2026-98352

Source
https://cve.org/CVERecord?id=CVE-2026-98352
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98352.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98352
Downstream
Published
2026-10-06T08:46:40Z
Modified
2026-10-07T02:47:34Z
Summary
RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted

The client borrows shared CQ credits in the ADDR_RESOLVED handler via ib_cq_pool_get(), before the peer is connected. create_cm() can return -ERESTARTSYS from wait_event_interruptible_timeout() without destroying the CM ID. The init_conns() and stop-and-destroy paths then call destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards rdma_destroy_id().

CMA serializes the handler against rdma_destroy_id() with handler_mutex, but that does not order the GET against destroy_con_cq_qp(). If ADDR_RESOLVED has already passed the DESTROYING check, it can take con_mutex, GET credits, and then lose the con to kfree. Device unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().

Set a per-connection flag under con_mutex before CQ/QP teardown so a racing ADDR_RESOLVED cannot borrow credits after teardown has begun.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98352.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3b89e92c2a95a39c38a3808f4528e502a39bd94d
Fixed
a82cca40139d9fcae8208901856bd5bb4051f097
Fixed
74c4ed55e61f1b65ddbebc5b635d136461a1c3da
Fixed
6f8020fe7465f49e234a576c04e415e9d08c7878
Fixed
31024e158b45358370a0a14ed96589e6aa62d6cb
Fixed
8f253d5893f991742464b9e7203c43fc08d0aa11
Fixed
bf88ac4867050112a6c819c8d1a7209bf48ef427
Fixed
2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98352.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98352.json"