Linux Kernel Vulnerability in RDMA/BNXT_RE Component
CVE-2026-98356

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98356?

A vulnerability in the Linux kernel's RDMA/bnxt_re component results from improper resource management during Data Center Bridging (DCB) setup. Specifically, the function 'bnxt_re_init_dcb_wq()' fails to check and handle allocations correctly, leading to the potential dereference of a NULL pointer within the async DCB handler when it invokes 'queue_work()'. This can lead to unexpected behavior or crashes, compromising system integrity. Prompt updates to the kernel are recommended to mitigate the risk associated with this vulnerability.

Affected Version(s)

Linux 51dc5312dcd929efea7647c0c0e75afa461531b5

Linux 51dc5312dcd929efea7647c0c0e75afa461531b5 < 727bbda37d9758960c346546004eea4ad49242e1

Linux 51dc5312dcd929efea7647c0c0e75afa461531b5 < 6c368f7baaea63c1c7c28c6df271511f2a1562c9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.