RDMA Vulnerability in Linux Kernel Affecting Multicast Group Management
CVE-2026-98360

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98360?

A vulnerability exists within the Linux kernel's RDMA subsystem where multicast group management could lead to resource mismanagement. The issue arises when a newly allocated multicast group is prematurely published in a management tree without ensuring that its corresponding Ethernet multicast address is successfully programmed. This flaw allows a local userspace RDMA client to encounter a situation where an error during address programming could leave a dangling reference to a freed multicast group structure. The fix addresses this by ensuring that the multicast group is kept private until the address programming succeeds, preventing concurrent access issues that could lead to use-after-free errors.

Affected Version(s)

Linux a926a903b7dc39a8a949150258c09290998dd812

Linux a926a903b7dc39a8a949150258c09290998dd812

Linux a926a903b7dc39a8a949150258c09290998dd812

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.