Linux Kernel Vulnerability in RDMA/rxe for Multiple Products
CVE-2026-98361
What is CVE-2026-98361?
In the Linux kernel, a vulnerability exists in the RDMA/rxe component that allows unprivileged users to register an ODP Memory Region (MR) over read-only mappings, leading to potential unauthorized modifications to sensitive files, such as /etc/passwd. This flaw stems from the removal of necessary access permission checks in the handling of read-only page faults. An attacker can exploit this by triggering incoming RDMA traffic, overriding data, and compromising the integrity of file systems without proper permissions. This vulnerability poses a serious security risk similar to previous exploits like Dirty COW.
Affected Version(s)
Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638
Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638 < 2d6c6f94d3e1cde049fe5db71dbd5549f10b2de1
Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638 < 769001ce838d907ecaa95f1d0a4e8fc86f761f9f