CVE-2026-98366

Source
https://cve.org/CVERecord?id=CVE-2026-98366
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98366.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98366
Downstream
Published
2026-10-06T08:46:51Z
Modified
2026-10-07T02:47:30Z
Summary
RDMA/rxe: validate access flags before swapping the MR's PD
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: validate access flags before swapping the MR's PD

rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument:

if (flags & IB_MR_REREG_PD) {
	rxe_put(old_pd);
	rxe_get(pd);
	mr->ibmr.pd = ibpd;
}

if (flags & IB_MR_REREG_ACCESS) {
	if (access & ~RXE_ACCESS_SUPPORTED_MR)
		return ERR_PTR(-EOPNOTSUPP);
	mr->access = access;
}

Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access check with mr->ibmr.pd already reassigned.

mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error without undoing the reassignment, so mr->pd == new_pd while the usecnts still charge the MR to orig_pd. ib_dereg_mr_user() then decrements new_pd, whose count can reach zero while a memory window still references it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup() writes to freed memory:

BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0 Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591 __rxe_put+0x31/0xa0 rxe_mw_cleanup+0x42/0x200 __rxe_cleanup+0x115/0x370 rxe_dealloc_mw+0x4c/0x80 Allocated by task 591: ib_uverbs_alloc_pd+0x258/0x540 Freed by task 591: ib_dealloc_pd_user+0x174/0x210 uverbs_free_pd+0x8d/0xc0 ib_uverbs_dealloc_pd+0x18e/0x1d0

Validate the access flags before mutating any state so the callback either applies every requested change or none.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98366.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Fixed
08f12745cb72981aa2cabe214af0c7a42a856f0a
Fixed
7230cc456d4bb2221c20c5f1d22b38b8576aa16f
Fixed
fe602c91a52e161ace4afd5bdb8f33270c554c6f
Fixed
4dd7a53f1c5b44693c26dac4b9b5bd5bb9d604c8
Fixed
ae36a5b609ae79f4de966328b78d2584be9719a4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98366.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98366.json"