๐Ÿ” CVE Alert

CVE-2026-98366

UNKNOWN 0.0

RDMA/rxe: validate access flags before swapping the MR's PD

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: validate access flags before swapping the MR's PD rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument: if (flags & IB_MR_REREG_PD) { rxe_put(old_pd); rxe_get(pd); mr->ibmr.pd = ibpd; } if (flags & IB_MR_REREG_ACCESS) { if (access & ~RXE_ACCESS_SUPPORTED_MR) return ERR_PTR(-EOPNOTSUPP); mr->access = access; } Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access check with mr->ibmr.pd already reassigned. mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error without undoing the reassignment, so mr->pd == new_pd while the usecnts still charge the MR to orig_pd. ib_dereg_mr_user() then decrements new_pd, whose count can reach zero while a memory window still references it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup() writes to freed memory: BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0 Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591 __rxe_put+0x31/0xa0 rxe_mw_cleanup+0x42/0x200 __rxe_cleanup+0x115/0x370 rxe_dealloc_mw+0x4c/0x80 Allocated by task 591: ib_uverbs_alloc_pd+0x258/0x540 Freed by task 591: ib_dealloc_pd_user+0x174/0x210 uverbs_free_pd+0x8d/0xc0 ib_uverbs_dealloc_pd+0x18e/0x1d0 Validate the access flags before mutating any state so the callback either applies every requested change or none.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c < 08f12745cb72981aa2cabe214af0c7a42a856f0a 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c < 7230cc456d4bb2221c20c5f1d22b38b8576aa16f 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c < fe602c91a52e161ace4afd5bdb8f33270c554c6f 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c < 4dd7a53f1c5b44693c26dac4b9b5bd5bb9d604c8 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c < ae36a5b609ae79f4de966328b78d2584be9719a4
Linux / Linux
6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/08f12745cb72981aa2cabe214af0c7a42a856f0a git.kernel.org: https://git.kernel.org/stable/c/7230cc456d4bb2221c20c5f1d22b38b8576aa16f git.kernel.org: https://git.kernel.org/stable/c/fe602c91a52e161ace4afd5bdb8f33270c554c6f git.kernel.org: https://git.kernel.org/stable/c/4dd7a53f1c5b44693c26dac4b9b5bd5bb9d604c8 git.kernel.org: https://git.kernel.org/stable/c/ae36a5b609ae79f4de966328b78d2584be9719a4