๐Ÿ” CVE Alert

CVE-2026-98367

UNKNOWN 0.0

RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window: siw_accept() ibv_modify_qp(ERROR) ---------------------- ---------------------- siw_qp_modify() fails up_write(&qp->state_lock) down_write(&qp->state_lock) nextstate_from_idle(): if (qp->cep) siw_cep_put(qp->cep) <- frees cep qp->cep = NULL goto error cep->qp = NULL <- UAF Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
6c52fdc244b5ccc468006fd65a504d4ee33743c7 < f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < e3f039082856adab7e195dea1af45d93dd6a3f1c 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < ad50d19f3d1ce052b3a146143581e930a1efb33e 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < 030306bbb9273af80f14d7af20129661964cd9a7 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < df2584750314336edcbcc21fb388e04b260f35b7 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < 9dcc0f4e488b70cff81e0e5717a498c929cf5de3 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < bfdc744bf20ae4c3ef2e470298de5237c5c9a13c 6c52fdc244b5ccc468006fd65a504d4ee33743c7 < 32cd87f54dd1070020e664ccb0312a9f0fea79b4
Linux / Linux
5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078 git.kernel.org: https://git.kernel.org/stable/c/e3f039082856adab7e195dea1af45d93dd6a3f1c git.kernel.org: https://git.kernel.org/stable/c/ad50d19f3d1ce052b3a146143581e930a1efb33e git.kernel.org: https://git.kernel.org/stable/c/030306bbb9273af80f14d7af20129661964cd9a7 git.kernel.org: https://git.kernel.org/stable/c/df2584750314336edcbcc21fb388e04b260f35b7 git.kernel.org: https://git.kernel.org/stable/c/9dcc0f4e488b70cff81e0e5717a498c929cf5de3 git.kernel.org: https://git.kernel.org/stable/c/bfdc744bf20ae4c3ef2e470298de5237c5c9a13c git.kernel.org: https://git.kernel.org/stable/c/32cd87f54dd1070020e664ccb0312a9f0fea79b4