Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98367— RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: RDMA/siw:当 siw_accept 中的 siw_qp_modify 失败时,需在锁的保护下清除关联 我们必须在释放 state_lock 之前清除 cep(连接端点),正如 siw_qp_llp_close 和 siw_qp_modify->siw_qp_llp_close 所做的那样。 否则,如果 siw_accept() 中的 siw_qp_modify() 失败,则在错误路径清理完成之前,QP 的 state_lock 就会被释放。在此窗口期间,并发执行的

CVSS 7.8 · High EPSS 0.13% · P2

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7< f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078 affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< e3f039082856adab7e195dea1af45d93dd6a3f1c affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< ad50d19f3d1ce052b3a146143581e930a1efb33e affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< 030306bbb9273af80f14d7af20129661964cd9a7 affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< df2584750314336edcbcc21fb388e04b260f35b7 affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< 9dcc0f4e488b70cff81e0e5717a498c929cf5de3 affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< bfdc744bf20ae4c3ef2e470298de5237c5c9a13c affected
6c52fdc244b5ccc468006fd65a504d4ee33743c7< 32cd87f54dd1070020e664ccb0312a9f0fea79b4 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98367

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept We need to clear cep before release state_lock as siw_qp_llp_close and siw_qp_modify->siw_qp_llp_close did. Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock is released before the error path cleanup. A concurrent ibv_modify_qp() transitioning the QP to ERROR can race in this window: siw_accept() ibv_modify_qp(ERROR) ---------------------- ---------------------- siw_qp_modify() fails up_write(&qp->state_lock) down_write(&qp->state_lock) nextstate_from_idle(): if (qp->cep) siw_cep_put(qp->cep) <- frees cep qp->cep = NULL goto error cep->qp = NULL <- UAF Clear qp->cep and drop the association reference taken by siw_cep_get(), all under the write lock held from the initial down_write(&qp->state_lock). Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free the cep before siw_accept() is done with it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7 ~ f11e09fe2fc3a11ccdf8f932b68181b0bb1d2078 -
Linux Linux 5.3 -

II. Public POCs for CVE-2026-98367

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98367

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98367 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98253 7.8 HIGH RDMA/ucma: Serialize join and leave on copy_to_user failure
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98367

No comments yet


Leave a comment