{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98253","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.331Z","datePublished":"2026-10-06T08:45:20.077Z","dateUpdated":"2026-10-07T06:49:41.019Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:41.019Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Serialize join and leave on copy_to_user failure\n\nrdma_join_multicast() queues RoCE work that later reads the ucma_multicast\nthrough event->param.ud.private_data, then list_add()s the CMA multicast\nat the head of id_priv->mc_list. rdma_leave_multicast() matches only by\nsockaddr and destroys the first hit.\n\nucma_process_join() used to drop ctx->mutex after a successful join and\nretake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls\nwith the same address can therefore insert a second CMA entry before the\nfirst thread's leave. leave then cancels the newer work and the older\nworker still dereferences the ucma_multicast that the first thread frees.\n\nKeep ctx->mutex held from rdma_join_multicast() through copy_to_user() and,\non -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.\nDo not leave if join itself failed: that path never published this address\non mc_list, and a leave-by-addr would destroy an earlier successful join."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached by write() of RDMA_USER_CM_CMD_JOIN_MCAST/JOIN_IP_MCAST on the local char device /dev/infiniband/rdma_cm into ucma_process_join(). The trigger is local: two racing joins and a bad response pointer. No remote peer supplies the data that causes it, so AV:L.\nAC:L - The attacker drives every part of the race. They make copy_to_user() fail with a bad cmd->response pointer, and a second thread issues JOIN_MCAST for the same address while ctx->mutex is dropped. rdma_leave_multicast() then destroys the newer mc_list head and cancels the wrong iboe_join work. The attempt can be repeated until it wins.\nPR:L - rdma_cm is created with mode 0666 and ucma_write() does no capability check. Any local user on a host with a RoCE port can create a UD cm_id, bind it and join multicast. An unprivileged user cannot create a soft-RoCE device, because nldev NEWLINK needs CAP_NET_ADMIN in the initial namespace, so the RoCE port must already exist.\nUI:N - The attacker triggers the bug entirely through their own writes on an rdma_cm file descriptor they opened. No other user or administrator has to act.\nS:U - The freed ucma_multicast and the corrupted kernel heap are in the same kernel security authority. This is local kernel memory corruption, not a VM or IOMMU boundary crossing.\nC:H - cma_iboe_join_work_handler() calls ucma_create_uevent() on the freed ucma_multicast, reading mc->uid and mc->id into the event that GET_EVENT copies to userspace. If the freed slot is reclaimed with sprayed objects, this use-after-free gives a read primitive.\nI:H - uevent->mc keeps a pointer to the freed ucma_multicast, and ucma_get_event() then runs uevent->mc->events_reported++. That is an attacker-timed write into freed and reclaimable slab memory, usable to corrupt an object sprayed into the slot.\nA:H - The use-after-free of ucma_multicast in the RoCE join worker and in ucma_get_event() can corrupt the slab or oops the kernel, crashing the host. Syzbot reported this bug (extid a6ffe86390c8a6afc818)."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/ucma.c"],"versions":[{"version":"60d613b39e8d0c9f3b526e9c96445422b4562d76","lessThan":"29b9ed83d8bfab5c6e11fcbf1aa836aa4ae26cb9","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"52172e11bd074ccaded21740ffeb67123f01dd00","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"01e29d0d78a8f66f221625720a04939eef5ec1f6","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"ae805d204cf1f15b87d1bf3529b4c649f3519420","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"43c4e24bd10370fc976f6220518049ce71419399","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"01cbdb724c584d7772fd25af2e4dfdf8527ce0d5","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"83610ee5e498fa5bfcb80031d2b959baea276bf6","status":"affected","versionType":"git"},{"version":"fe454dc31e84f8c14cb8942fcb61666c9f40745b","lessThan":"662ade4de9ff5eceb0820a9f8e9fac70ba6a815b","status":"affected","versionType":"git"},{"version":"a3262b3884dd67b4c5632ce7cdf9cff9d1a575d4","status":"affected","versionType":"git"},{"version":"5.10.20","lessThan":"5.10.271","status":"affected","versionType":"semver"},{"version":"5.11.3","lessThan":"5.12","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/ucma.c"],"versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.20","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12","versionEndExcluding":"7.3-rc4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/29b9ed83d8bfab5c6e11fcbf1aa836aa4ae26cb9"},{"url":"https://git.kernel.org/stable/c/52172e11bd074ccaded21740ffeb67123f01dd00"},{"url":"https://git.kernel.org/stable/c/01e29d0d78a8f66f221625720a04939eef5ec1f6"},{"url":"https://git.kernel.org/stable/c/ae805d204cf1f15b87d1bf3529b4c649f3519420"},{"url":"https://git.kernel.org/stable/c/43c4e24bd10370fc976f6220518049ce71419399"},{"url":"https://git.kernel.org/stable/c/01cbdb724c584d7772fd25af2e4dfdf8527ce0d5"},{"url":"https://git.kernel.org/stable/c/83610ee5e498fa5bfcb80031d2b959baea276bf6"},{"url":"https://git.kernel.org/stable/c/662ade4de9ff5eceb0820a9f8e9fac70ba6a815b"}],"title":"RDMA/ucma: Serialize join and leave on copy_to_user failure","x_generator":{"engine":"bippy-1.2.0"}}}}