{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98367","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.344Z","datePublished":"2026-10-06T08:46:52.452Z","dateUpdated":"2026-10-07T06:50:20.775Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:20.775Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept\n\nWe need to clear cep before release state_lock as siw_qp_llp_close and\nsiw_qp_modify->siw_qp_llp_close did.\n\nOtherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock\nis released before the error path cleanup. A concurrent ibv_modify_qp()\ntransitioning the QP to ERROR can race in this window:\n\n  siw_accept()                       ibv_modify_qp(ERROR)\n  ----------------------             ----------------------\n  siw_qp_modify() fails\n  up_write(&qp->state_lock)\n                                     down_write(&qp->state_lock)\n                                     nextstate_from_idle():\n\t\t\t\t     if (qp->cep)\n                                       siw_cep_put(qp->cep) <- frees cep\n                                       qp->cep = NULL\n  goto error\n    cep->qp = NULL                   <- UAF\n\nClear qp->cep and drop the association reference taken by siw_cep_get(),\nall under the write lock held from the initial down_write(&qp->state_lock).\nThread B therefore sees qp->cep == NULL, skips its own put, and cannot free\nthe cep before siw_accept() is done with it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - siw_accept() is called through the ops.iw_accept hook from iw_cm_accept(), which a local process reaches with the RDMA_USER_CM_CMD_ACCEPT command on /dev/infiniband/rdma_cm. The racing side is the uverbs MODIFY_QP command (ibv_modify_qp to ERROR), also local. No wire message carries data that causes the siw_qp_modify() failure, so the attack is local.\nAC:L - The attacker does control both racing threads, since it owns the QP and issues the accept and modify_qp calls itself. Even so, AC is High: in siw_accept the only way siw_qp_modify() can fail is siw_qp_readq_init() hitting a vcalloc() ENOMEM, and IRD/ORD are capped at 128, so the allocations are small. That failure depends on system-wide memory exhaustion, which the attacker cannot produce on demand.\nPR:L - Running rdma_accept and ibv_modify_qp on a QP the user created on an existing siw device needs only ordinary access to the rdma_cm and uverbs device nodes. Creating the siw link through RDMA_NLDEV_CMD_NEWLINK is admin-only, but no privilege is needed to use a device that already exists.\nUI:N - The attacker drives both siw_accept() and the concurrent ibv_modify_qp(ERROR) through their own rdma_cm and verbs calls, and the connecting peer can be the attacker over loopback. No other user has to do anything.\nS:U - The freed siw_cep and the writes into it both stay inside the kernel's own security authority. No VM, IOMMU or sandbox boundary is crossed.\nC:H - siw_qp_nextstate_from_idle() frees the siw_cep by calling siw_cep_put(qp->cep). The error path in siw_accept() then keeps using that freed object: it writes cep->qp = NULL, runs siw_free_cm_id, and calls siw_cep_set_free_and_put. A reclaimed object in that slot gives the attacker a use-after-free primitive that can be built into a kernel memory leak.\nI:H - After the free, the error path writes cep->qp = NULL and does kref and lock operations on the dead siw_cep. That corrupts whatever object has taken over the slot, and this kind of UAF write can be used to corrupt kernel data or hijack control flow.\nA:H - A kref_put or lock operation on the freed siw_cep in siw_cep_set_free_and_put can corrupt the slab or oops the kernel, and that crashes the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/siw/siw_cm.c"],"versions":[{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"e3f039082856adab7e195dea1af45d93dd6a3f1c","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"ad50d19f3d1ce052b3a146143581e930a1efb33e","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"030306bbb9273af80f14d7af20129661964cd9a7","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"df2584750314336edcbcc21fb388e04b260f35b7","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"9dcc0f4e488b70cff81e0e5717a498c929cf5de3","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"bfdc744bf20ae4c3ef2e470298de5237c5c9a13c","status":"affected","versionType":"git"},{"version":"6c52fdc244b5ccc468006fd65a504d4ee33743c7","lessThan":"32cd87f54dd1070020e664ccb0312a9f0fea79b4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/siw/siw_cm.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078"},{"url":"https://git.kernel.org/stable/c/e3f039082856adab7e195dea1af45d93dd6a3f1c"},{"url":"https://git.kernel.org/stable/c/ad50d19f3d1ce052b3a146143581e930a1efb33e"},{"url":"https://git.kernel.org/stable/c/030306bbb9273af80f14d7af20129661964cd9a7"},{"url":"https://git.kernel.org/stable/c/df2584750314336edcbcc21fb388e04b260f35b7"},{"url":"https://git.kernel.org/stable/c/9dcc0f4e488b70cff81e0e5717a498c929cf5de3"},{"url":"https://git.kernel.org/stable/c/bfdc744bf20ae4c3ef2e470298de5237c5c9a13c"},{"url":"https://git.kernel.org/stable/c/32cd87f54dd1070020e664ccb0312a9f0fea79b4"}],"title":"RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept","x_generator":{"engine":"bippy-1.2.0"}}}}