« Volver al listado

CVE-2026-98367

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept

We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did.

Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window:

Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it.

Detalles técnicos trazas, registros y código del informe original
  siw_accept()                       ibv_modify_qp(ERROR)
  ----------------------             ----------------------
  siw_qp_modify() fails
  up_write(&qp->state_lock)
                                     down_write(&qp->state_lock)
                                     nextstate_from_idle():
				     if (qp->cep)
                                       siw_cep_put(qp->cep) <- frees cep
                                       qp->cep = NULL
  goto error
    cep->qp = NULL                   <- UAF

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98367",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "e3f039082856adab7e195dea1af45d93dd6a3f1c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "ad50d19f3d1ce052b3a146143581e930a1efb33e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "030306bbb9273af80f14d7af20129661964cd9a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "df2584750314336edcbcc21fb388e04b260f35b7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "9dcc0f4e488b70cff81e0e5717a498c929cf5de3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "bfdc744bf20ae4c3ef2e470298de5237c5c9a13c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
              "lessThan": "32cd87f54dd1070020e664ccb0312a9f0fea79b4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_cm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_cm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:30.970",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/030306bbb9273af80f14d7af20129661964cd9a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/32cd87f54dd1070020e664ccb0312a9f0fea79b4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9dcc0f4e488b70cff81e0e5717a498c929cf5de3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ad50d19f3d1ce052b3a146143581e930a1efb33e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfdc744bf20ae4c3ef2e470298de5237c5c9a13c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/df2584750314336edcbcc21fb388e04b260f35b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3f039082856adab7e195dea1af45d93dd6a3f1c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept\n\nWe need to clear cep before release state_lock as siw_qp_llp_close and\nsiw_qp_modify->siw_qp_llp_close did.\n\nOtherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock\nis released before the error path cleanup. A concurrent ibv_modify_qp()\ntransitioning the QP to ERROR can race in this window:\n\n  siw_accept()                       ibv_modify_qp(ERROR)\n  ----------------------             ----------------------\n  siw_qp_modify() fails\n  up_write(&qp->state_lock)\n                                     down_write(&qp->state_lock)\n                                     nextstate_from_idle():\n\t\t\t\t     if (qp->cep)\n                                       siw_cep_put(qp->cep) <- frees cep\n                                       qp->cep = NULL\n  goto error\n    cep->qp = NULL                   <- UAF\n\nClear qp->cep and drop the association reference taken by siw_cep_get(),\nall under the write lock held from the initial down_write(&qp->state_lock).\nThread B therefore sees qp->cep == NULL, skips its own put, and cannot free\nthe cep before siw_accept() is done with it."
    }
  ],
  "lastModified": "2026-10-06T09:18:30.970",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}