Linux Kernel RDMA/siw Vulnerability in Multiple Products
CVE-2026-98367

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98367?

The Linux kernel presents a vulnerability in the RDMA/siw subsystem where improper error handling during the siw_accept operation may lead to use-after-free conditions. If the siw_qp_modify function fails, the state lock is released prematurely, allowing for concurrent modifications that could lead to potential exploitation of the QP's association. This defect raises significant security concerns as it may allow unauthorized access or manipulation of the kernel's memory.

Affected Version(s)

Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7

Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7

Linux 6c52fdc244b5ccc468006fd65a504d4ee33743c7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.