{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98360","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.344Z","datePublished":"2026-10-06T08:46:46.743Z","dateUpdated":"2026-10-07T06:50:14.996Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:14.996Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe->mcg_tree before programming the backing Ethernet multicast address\nwith rxe_mcast_add(), which runs outside mcg_lock. A local userspace\nRDMA client reaches this path with ATTACH_MCAST on a UD QP; if\nrxe_mcast_add() then returns an error (for example -ENODEV when the\nbacking netdev has been removed, or a propagated dev_mc_add() error),\nthe unwind frees the published group without removing it from the tree.\nA later lookup of the same MGID dereferences the freed struct rxe_mcg\nfrom __rxe_lookup_mcg().\n\nFix this by keeping the new mcg private until rxe_mcast_add() succeeds.\nSplit the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()\nbefore taking the tree reference, and free the still-private mcg on\nfailure. Because the group is never visible in mcg_tree until the\nmulticast address is programmed, no concurrent caller can look it up or\nattach a QP to a group that is about to be torn down, so the error path\nneeds no conditional unwind. If another caller publishes the same MGID\nwhile the address is being programmed, the post-add re-check under\nmcg_lock finds the winner; this caller then drops its private object and\nbalances its own rxe_mcast_add() with rxe_mcast_del() before returning\nthe winner.\n\nReproduced by forcing the rxe_mcast_add() error return under KASAN:\nwithout the change the next attach to the same MGID reports a\nslab-use-after-free in __rxe_lookup_mcg(); with it the forced failure\nreturns cleanly. A no-injection attach/detach regression, including a\ntwo-QP shared join/leave and re-attach, stays KASAN- and leak-clean."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The faulty publish-then-free sequence is in rxe_get_mcg(), reached from the uverbs ATTACH_MCAST command (ib_uverbs_attach_mcast -> ib_attach_mcast -> rxe_attach_mcast) on a local UD QP. A remote RoCEv2 multicast packet (rxe_rcv_mcast_pkt -> rxe_lookup_mcg) can only hit the stale node after a local caller has already caused the failure.\nAC:H - The dangling mcg is only left behind when rxe_mcast_add() fails after the group is published. That needs ib_device_get_netdev() to return NULL while the rxe netdev is being unregistered (an admin or hardware event), or a GFP_ATOMIC failure in __hw_addr_create(). An unprivileged user cannot produce either on demand.\nPR:L - ib_uverbs_attach_mcast() and rxe_attach_mcast() have no capability check, so any user who can open the rxe uverbs device and create a UD QP can drive rxe_get_mcg(). Creating the rxe link itself (RDMA_NL_ADMIN_PERM, checked with netlink_capable against the init namespace) is admin setup the attacker does not perform.\nUI:N - The attacker issues ATTACH_MCAST for the failing MGID and then the follow-up attach/detach/lookup themselves; no other user has to act.\nS:U - The freed rxe_mcg is kernel heap memory in the same kernel security authority; there is no VM, IOMMU or sandbox boundary crossed.\nC:H - The freed struct rxe_mcg stays linked in rxe->mcg_tree. __rxe_lookup_mcg() walks its rb_node and mgid, and later code follows its qp_list, so reallocating that slab slot with attacker-chosen data gives a heap read primitive.\nI:H - After the free, __rxe_lookup_mcg() does kref_get() on the stale object, and rxe_attach_mcg() list_add()s an mca into its qp_list and updates qp_num. These are writes into reallocated memory, and the rb-tree insert/erase relinks through the freed node.\nA:H - The next ATTACH_MCAST, detach, or received multicast lookup for that MGID dereferences the freed rxe_mcg (KASAN slab-use-after-free in __rxe_lookup_mcg()), corrupting the rb-tree and crashing the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mcast.c"],"versions":[{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"ddb43ac0926d4a931bc9b7744b93627f627457e5","status":"affected","versionType":"git"},{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"c79a789aa15180a1543b5db49c343d12e3ec214d","status":"affected","versionType":"git"},{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"faae1fb4ccf8205806a8802c008798dabeb0205b","status":"affected","versionType":"git"},{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"02c0a2fa69c16248a7432af8a6d64ab2a73a5283","status":"affected","versionType":"git"},{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"d4fc4e37f8a143b0fe83b42c8fb48cf542154fee","status":"affected","versionType":"git"},{"version":"a926a903b7dc39a8a949150258c09290998dd812","lessThan":"1caceeb2d74bbe88223aea55eb8626b4c5f076fd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mcast.c"],"versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ddb43ac0926d4a931bc9b7744b93627f627457e5"},{"url":"https://git.kernel.org/stable/c/c79a789aa15180a1543b5db49c343d12e3ec214d"},{"url":"https://git.kernel.org/stable/c/faae1fb4ccf8205806a8802c008798dabeb0205b"},{"url":"https://git.kernel.org/stable/c/02c0a2fa69c16248a7432af8a6d64ab2a73a5283"},{"url":"https://git.kernel.org/stable/c/d4fc4e37f8a143b0fe83b42c8fb48cf542154fee"},{"url":"https://git.kernel.org/stable/c/1caceeb2d74bbe88223aea55eb8626b4c5f076fd"}],"title":"RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds","x_generator":{"engine":"bippy-1.2.0"}}}}