Linux Kernel Security Flaw in RDMA Implementation
CVE-2026-98354

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98354?

A vulnerability exists in the Linux kernel's RDMA subsystem where a buffer leak occurs during PKey enforcement failures. Specifically, the function ib_mad_complete_recv() fails to properly manage memory when a security check does not pass. This can lead to unintended memory retention, as the buffer is never released under certain error conditions. An attacker could exploit this by repeatedly sending messages with incorrect PKeys, effectively consuming system resources and leading to potential service degradation.

Affected Version(s)

Linux 47a2b338fe63200d716d2e24131cdb49f17c77da < 4617c9a856188674dddb0ca66979746d07688579

Linux 47a2b338fe63200d716d2e24131cdb49f17c77da < 8e2036fb47a5b152d53eadbd35abf311bd34cc7f

Linux 47a2b338fe63200d716d2e24131cdb49f17c77da

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.