๐Ÿ” CVE Alert

CVE-2026-98354

UNKNOWN 0.0

RDMA/mad: Fix receive buffer leak when PKey enforcement fails

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Fix receive buffer leak when PKey enforcement fails ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs ib_mad_enforce_security() before linking recv_buf onto that list. On failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees the ib_mad_private of every buffer found there. As the list is still empty at that point, nothing is freed at all. The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL right after ib_mad_complete_recv() returns, assuming the MAD layer took ownership of the buffer. Every MAD that fails the PKey check therefore leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA), and a remote node can trigger this repeatedly by sending MADs with a wrong PKey. Link recv_buf onto rmpp_list right after the list is initialized, so the error path has something to free.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
47a2b338fe63200d716d2e24131cdb49f17c77da < 4617c9a856188674dddb0ca66979746d07688579 47a2b338fe63200d716d2e24131cdb49f17c77da < 8e2036fb47a5b152d53eadbd35abf311bd34cc7f 47a2b338fe63200d716d2e24131cdb49f17c77da < bad289e42f512646a988f278f536d21547df73f1 47a2b338fe63200d716d2e24131cdb49f17c77da < 752b30e9d339008e5ce7eed412e9446078916129 47a2b338fe63200d716d2e24131cdb49f17c77da < 39c4ea72a40503e102ae07e6776005f96ca078a6 47a2b338fe63200d716d2e24131cdb49f17c77da < 5091e25ec503f7fc02723ca435226467b68caac7 47a2b338fe63200d716d2e24131cdb49f17c77da < c0d8df85db146d6275e226cb950023be69dd6c77 47a2b338fe63200d716d2e24131cdb49f17c77da < 3476c28c9addfa253f505e6bd87f1f5598b961d0
Linux / Linux
4.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4617c9a856188674dddb0ca66979746d07688579 git.kernel.org: https://git.kernel.org/stable/c/8e2036fb47a5b152d53eadbd35abf311bd34cc7f git.kernel.org: https://git.kernel.org/stable/c/bad289e42f512646a988f278f536d21547df73f1 git.kernel.org: https://git.kernel.org/stable/c/752b30e9d339008e5ce7eed412e9446078916129 git.kernel.org: https://git.kernel.org/stable/c/39c4ea72a40503e102ae07e6776005f96ca078a6 git.kernel.org: https://git.kernel.org/stable/c/5091e25ec503f7fc02723ca435226467b68caac7 git.kernel.org: https://git.kernel.org/stable/c/c0d8df85db146d6275e226cb950023be69dd6c77 git.kernel.org: https://git.kernel.org/stable/c/3476c28c9addfa253f505e6bd87f1f5598b961d0