Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98354— RDMA/mad: Fix receive buffer leak when PKey enforcement fails

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: RDMA/mad:修复 PKey 强制策略失败时接收缓冲区泄漏的问题 函数首先初始化 ,然后调用 执行安全策略检查,之后才将 链接到该列表中。当安全策略检查失败时,该函数会调用 ,而该函数仅遍历 并释放列表中每个缓冲区所关联的 结构。由于此时列表仍为空,因此实际上没有释放任何内存。 调用方也无法完成清理工作: 在 返回后立即将 设置为 NULL,其假设是 MAD 层已接管缓冲区的所有权。因此,每次 PKey 检查失败的 MAD 都会导致一个 (约 300 字节,针对每个 I

AI Predicted 5.3 Difficulty: Moderate EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1498 · Network Denial of Service

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da< 4617c9a856188674dddb0ca66979746d07688579 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< 8e2036fb47a5b152d53eadbd35abf311bd34cc7f affected
47a2b338fe63200d716d2e24131cdb49f17c77da< bad289e42f512646a988f278f536d21547df73f1 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< 752b30e9d339008e5ce7eed412e9446078916129 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< 39c4ea72a40503e102ae07e6776005f96ca078a6 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< 5091e25ec503f7fc02723ca435226467b68caac7 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< c0d8df85db146d6275e226cb950023be69dd6c77 affected
47a2b338fe63200d716d2e24131cdb49f17c77da< 3476c28c9addfa253f505e6bd87f1f5598b961d0 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98354

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Fix receive buffer leak when PKey enforcement fails ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs ib_mad_enforce_security() before linking recv_buf onto that list. On failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees the ib_mad_private of every buffer found there. As the list is still empty at that point, nothing is freed at all. The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL right after ib_mad_complete_recv() returns, assuming the MAD layer took ownership of the buffer. Every MAD that fails the PKey check therefore leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA), and a remote node can trigger this repeatedly by sending MADs with a wrong PKey. Link recv_buf onto rmpp_list right after the list is initialized, so the error path has something to free.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da ~ 4617c9a856188674dddb0ca66979746d07688579 -
Linux Linux 4.13 -

II. Public POCs for CVE-2026-98354

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98354

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98354 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98354

No comments yet


Leave a comment