CVE-2026-98367
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did.
Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window:
Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it.
Detalles técnicos trazas, registros y código del informe original
siw_accept() ibv_modify_qp(ERROR)
---------------------- ----------------------
siw_qp_modify() fails
up_write(&qp->state_lock)
down_write(&qp->state_lock)
nextstate_from_idle():
if (qp->cep)
siw_cep_put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAFCVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/030306bbb9273af80f14d7af20129661964cd9a7
- https://git.kernel.org/stable/c/32cd87f54dd1070020e664ccb0312a9f0fea79b4
- https://git.kernel.org/stable/c/9dcc0f4e488b70cff81e0e5717a498c929cf5de3
- https://git.kernel.org/stable/c/ad50d19f3d1ce052b3a146143581e930a1efb33e
- https://git.kernel.org/stable/c/bfdc744bf20ae4c3ef2e470298de5237c5c9a13c
- https://git.kernel.org/stable/c/df2584750314336edcbcc21fb388e04b260f35b7
- https://git.kernel.org/stable/c/e3f039082856adab7e195dea1af45d93dd6a3f1c
- https://git.kernel.org/stable/c/f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98367",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "e3f039082856adab7e195dea1af45d93dd6a3f1c",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "ad50d19f3d1ce052b3a146143581e930a1efb33e",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "030306bbb9273af80f14d7af20129661964cd9a7",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "df2584750314336edcbcc21fb388e04b260f35b7",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "9dcc0f4e488b70cff81e0e5717a498c929cf5de3",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "bfdc744bf20ae4c3ef2e470298de5237c5c9a13c",
"versionType": "git"
},
{
"status": "affected",
"version": "6c52fdc244b5ccc468006fd65a504d4ee33743c7",
"lessThan": "32cd87f54dd1070020e664ccb0312a9f0fea79b4",
"versionType": "git"
}
],
"programFiles": [
"drivers/infiniband/sw/siw/siw_cm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/infiniband/sw/siw/siw_cm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:30.970",
"references": [
{
"url": "https://git.kernel.org/stable/c/030306bbb9273af80f14d7af20129661964cd9a7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/32cd87f54dd1070020e664ccb0312a9f0fea79b4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9dcc0f4e488b70cff81e0e5717a498c929cf5de3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ad50d19f3d1ce052b3a146143581e930a1efb33e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bfdc744bf20ae4c3ef2e470298de5237c5c9a13c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/df2584750314336edcbcc21fb388e04b260f35b7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e3f039082856adab7e195dea1af45d93dd6a3f1c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept\n\nWe need to clear cep before release state_lock as siw_qp_llp_close and\nsiw_qp_modify->siw_qp_llp_close did.\n\nOtherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock\nis released before the error path cleanup. A concurrent ibv_modify_qp()\ntransitioning the QP to ERROR can race in this window:\n\n siw_accept() ibv_modify_qp(ERROR)\n ---------------------- ----------------------\n siw_qp_modify() fails\n up_write(&qp->state_lock)\n down_write(&qp->state_lock)\n nextstate_from_idle():\n\t\t\t\t if (qp->cep)\n siw_cep_put(qp->cep) <- frees cep\n qp->cep = NULL\n goto error\n cep->qp = NULL <- UAF\n\nClear qp->cep and drop the association reference taken by siw_cep_get(),\nall under the write lock held from the initial down_write(&qp->state_lock).\nThread B therefore sees qp->cep == NULL, skips its own put, and cannot free\nthe cep before siw_accept() is done with it."
}
],
"lastModified": "2026-10-06T09:18:30.970",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}