CVE-2026-98354

Source
https://cve.org/CVERecord?id=CVE-2026-98354
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98354.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98354
Downstream
Published
2026-10-06T08:46:41Z
Modified
2026-10-07T02:47:34Z
Summary
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mad: Fix receive buffer leak when PKey enforcement fails

ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs ib_mad_enforce_security() before linking recv_buf onto that list. On failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees the ib_mad_private of every buffer found there. As the list is still empty at that point, nothing is freed at all.

The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL right after ib_mad_complete_recv() returns, assuming the MAD layer took ownership of the buffer. Every MAD that fails the PKey check therefore leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA), and a remote node can trigger this repeatedly by sending MADs with a wrong PKey.

Link recv_buf onto rmpp_list right after the list is initialized, so the error path has something to free.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98354.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
47a2b338fe63200d716d2e24131cdb49f17c77da
Fixed
4617c9a856188674dddb0ca66979746d07688579
Fixed
8e2036fb47a5b152d53eadbd35abf311bd34cc7f
Fixed
bad289e42f512646a988f278f536d21547df73f1
Fixed
752b30e9d339008e5ce7eed412e9446078916129
Fixed
39c4ea72a40503e102ae07e6776005f96ca078a6
Fixed
5091e25ec503f7fc02723ca435226467b68caac7
Fixed
c0d8df85db146d6275e226cb950023be69dd6c77
Fixed
3476c28c9addfa253f505e6bd87f1f5598b961d0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98354.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98354.json"