{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98252","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.331Z","datePublished":"2026-10-06T08:45:19.393Z","dateUpdated":"2026-10-07T06:49:39.868Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:39.868Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: fix refcount bug in iwpm_get_nlmsg_request()\n\niwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()\nmaking it accessible to global list where another CPU can kref_get()\non nlmsg_request causing a refcount \"addition on 0\" bug. Fix this\nby initializing kref _before_ list_add_tail() so refcount for\nnlmsg_request can be incremented/decremented normally. In addition,\nalso initialize every field before list_add_tail()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The triggering input is a forged IWPM reply (e.g. RDMA_NL_IWPM_REG_PID) sent over a local NETLINK_RDMA socket to iwcm_nl_cb_table callbacks, which call iwpm_find_nlmsg_request(). No remote protocol carries it, and rdma_nl_rcv_msg() rejects RDMA_NL_IWCM messages from outside init_net.\nAC:H - The forged reply must land in the few-instruction gap between list_add_tail() and kref_init()/sema_init() in iwpm_get_nlmsg_request(). The host also needs an iWARP device so that iw_cm_map() sends port-mapper requests, and the attacker cannot set that up.\nPR:L - No iwcm_nl_cb_table entry sets RDMA_NL_ADMIN_PERM, and the NETLINK_RDMA socket uses NL_CFG_F_NONROOT_RECV, so an unprivileged user in the initial netns can join RDMA_NL_GROUP_IWPM, read the sequence numbers and send replies. A local login is still needed.\nUI:N - The attacker sends the netlink replies and starts iWARP connection setup without any action from another user.\nS:U - The memory corruption stays inside the kernel's own security authority. No guest/host or IOMMU boundary is crossed.\nC:H - kref_init() erases the reference taken by iwpm_find_nlmsg_request(), so the requester's kref_put() in iwpm_wait_complete_req() can free the kmalloc'd iwpm_nlmsg_request while iwpm_register_pid_cb() still uses it. That is a use-after-free that can be reclaimed by sprayed data.\nI:H - After the early free, the callback's up(&nlmsg_request->sem) and the requester's down_timeout() write a semaphore inside a freed and possibly reclaimed slab object. That is a use-after-free write on heap memory.\nA:H - The race fires a refcount_t 'addition on 0' WARN (a panic under panic_on_warn), and the replies can dereference NULL req_buffer in iwpm_register_pid_cb() or touch freed memory, either of which oopses the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/iwpm_util.c"],"versions":[{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"52c13c63bb3662c108244e7447055e30bf40244e","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"8a91609032d47e77bcb37bc8f6e88d89340d2709","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"ce8a379598bd4058081416abea4279fd05a95374","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"88e429a4e9bac3d2138011c5ca06254331f2587f","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"e15eb536be4f646ce683d2867572b2200be877f7","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"117871cdb8927542abd7b65ce5995bf0265a8c05","status":"affected","versionType":"git"},{"version":"30dc5e63d6a5ad24894b5512d10b228d73645a44","lessThan":"33fb59da49c4c3f5c2ec9f9d4447a56857a02c02","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/iwpm_util.c"],"versions":[{"version":"3.16","status":"affected"},{"version":"0","lessThan":"3.16","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/52c13c63bb3662c108244e7447055e30bf40244e"},{"url":"https://git.kernel.org/stable/c/8a91609032d47e77bcb37bc8f6e88d89340d2709"},{"url":"https://git.kernel.org/stable/c/ce8a379598bd4058081416abea4279fd05a95374"},{"url":"https://git.kernel.org/stable/c/2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8"},{"url":"https://git.kernel.org/stable/c/88e429a4e9bac3d2138011c5ca06254331f2587f"},{"url":"https://git.kernel.org/stable/c/e15eb536be4f646ce683d2867572b2200be877f7"},{"url":"https://git.kernel.org/stable/c/117871cdb8927542abd7b65ce5995bf0265a8c05"},{"url":"https://git.kernel.org/stable/c/33fb59da49c4c3f5c2ec9f9d4447a56857a02c02"}],"title":"RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()","x_generator":{"engine":"bippy-1.2.0"}}}}