Linux Kernel RDMA/siw Vulnerability in Multiple Products
CVE-2026-98367
Currently unrated
What is CVE-2026-98367?
The Linux kernel presents a vulnerability in the RDMA/siw subsystem where improper error handling during the siw_accept operation may lead to use-after-free conditions. If the siw_qp_modify function fails, the state lock is released prematurely, allowing for concurrent modifications that could lead to potential exploitation of the QP's association. This defect raises significant security concerns as it may allow unauthorized access or manipulation of the kernel's memory.
Affected Version(s)
Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7
Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7
Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7