CVE-2026-98252 (GCVE-0-2026-98252)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-07 06:49
VLAI
Title
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref _before_ list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().
Impacted products
Vendor Product Version
Linux Linux Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 52c13c63bb3662c108244e7447055e30bf40244e (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 8a91609032d47e77bcb37bc8f6e88d89340d2709 (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < ce8a379598bd4058081416abea4279fd05a95374 (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8 (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 88e429a4e9bac3d2138011c5ca06254331f2587f (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < e15eb536be4f646ce683d2867572b2200be877f7 (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 117871cdb8927542abd7b65ce5995bf0265a8c05 (git)
Affected: 30dc5e63d6a5ad24894b5512d10b228d73645a44 , < 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 (git)
Create a notification for this product.
Linux Linux Affected: 3.16
Unaffected: 0 , < 3.16 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/core/iwpm_util.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "52c13c63bb3662c108244e7447055e30bf40244e",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "8a91609032d47e77bcb37bc8f6e88d89340d2709",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "ce8a379598bd4058081416abea4279fd05a95374",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "88e429a4e9bac3d2138011c5ca06254331f2587f",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "e15eb536be4f646ce683d2867572b2200be877f7",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "117871cdb8927542abd7b65ce5995bf0265a8c05",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            },
            {
              "lessThan": "33fb59da49c4c3f5c2ec9f9d4447a56857a02c02",
              "status": "affected",
              "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/core/iwpm_util.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.16"
            },
            {
              "lessThan": "3.16",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "3.16",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: fix refcount bug in iwpm_get_nlmsg_request()\n\niwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()\nmaking it accessible to global list where another CPU can kref_get()\non nlmsg_request causing a refcount \"addition on 0\" bug. Fix this\nby initializing kref _before_ list_add_tail() so refcount for\nnlmsg_request can be incremented/decremented normally. In addition,\nalso initialize every field before list_add_tail()."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The triggering input is a forged IWPM reply (e.g. RDMA_NL_IWPM_REG_PID) sent over a local NETLINK_RDMA socket to iwcm_nl_cb_table callbacks, which call iwpm_find_nlmsg_request(). No remote protocol carries it, and rdma_nl_rcv_msg() rejects RDMA_NL_IWCM messages from outside init_net.\nAC:H - The forged reply must land in the few-instruction gap between list_add_tail() and kref_init()/sema_init() in iwpm_get_nlmsg_request(). The host also needs an iWARP device so that iw_cm_map() sends port-mapper requests, and the attacker cannot set that up.\nPR:L - No iwcm_nl_cb_table entry sets RDMA_NL_ADMIN_PERM, and the NETLINK_RDMA socket uses NL_CFG_F_NONROOT_RECV, so an unprivileged user in the initial netns can join RDMA_NL_GROUP_IWPM, read the sequence numbers and send replies. A local login is still needed.\nUI:N - The attacker sends the netlink replies and starts iWARP connection setup without any action from another user.\nS:U - The memory corruption stays inside the kernel\u0027s own security authority. No guest/host or IOMMU boundary is crossed.\nC:H - kref_init() erases the reference taken by iwpm_find_nlmsg_request(), so the requester\u0027s kref_put() in iwpm_wait_complete_req() can free the kmalloc\u0027d iwpm_nlmsg_request while iwpm_register_pid_cb() still uses it. That is a use-after-free that can be reclaimed by sprayed data.\nI:H - After the early free, the callback\u0027s up(\u0026nlmsg_request-\u003esem) and the requester\u0027s down_timeout() write a semaphore inside a freed and possibly reclaimed slab object. That is a use-after-free write on heap memory.\nA:H - The race fires a refcount_t \u0027addition on 0\u0027 WARN (a panic under panic_on_warn), and the replies can dereference NULL req_buffer in iwpm_register_pid_cb() or touch freed memory, either of which oopses the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:39.868Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/52c13c63bb3662c108244e7447055e30bf40244e"
        },
        {
          "url": "https://git.kernel.org/stable/c/8a91609032d47e77bcb37bc8f6e88d89340d2709"
        },
        {
          "url": "https://git.kernel.org/stable/c/ce8a379598bd4058081416abea4279fd05a95374"
        },
        {
          "url": "https://git.kernel.org/stable/c/2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8"
        },
        {
          "url": "https://git.kernel.org/stable/c/88e429a4e9bac3d2138011c5ca06254331f2587f"
        },
        {
          "url": "https://git.kernel.org/stable/c/e15eb536be4f646ce683d2867572b2200be877f7"
        },
        {
          "url": "https://git.kernel.org/stable/c/117871cdb8927542abd7b65ce5995bf0265a8c05"
        },
        {
          "url": "https://git.kernel.org/stable/c/33fb59da49c4c3f5c2ec9f9d4447a56857a02c02"
        }
      ],
      "title": "RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98252",
    "datePublished": "2026-10-06T08:45:19.393Z",
    "dateReserved": "2026-09-25T10:25:14.331Z",
    "dateUpdated": "2026-10-07T06:49:39.868Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98252",
      "date": "2026-10-09",
      "epss": "0.00122",
      "percentile": "0.01775"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/infiniband/core/iwpm_util.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "52c13c63bb3662c108244e7447055e30bf40244e",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8a91609032d47e77bcb37bc8f6e88d89340d2709",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ce8a379598bd4058081416abea4279fd05a95374",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "88e429a4e9bac3d2138011c5ca06254331f2587f",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e15eb536be4f646ce683d2867572b2200be877f7",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "117871cdb8927542abd7b65ce5995bf0265a8c05",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "33fb59da49c4c3f5c2ec9f9d4447a56857a02c02",
                    "status": "affected",
                    "version": "30dc5e63d6a5ad24894b5512d10b228d73645a44",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/infiniband/core/iwpm_util.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.16"
                  },
                  {
                    "lessThan": "3.16",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: fix refcount bug in iwpm_get_nlmsg_request()\n\niwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()\nmaking it accessible to global list where another CPU can kref_get()\non nlmsg_request causing a refcount \"addition on 0\" bug. Fix this\nby initializing kref _before_ list_add_tail() so refcount for\nnlmsg_request can be incremented/decremented normally. In addition,\nalso initialize every field before list_add_tail()."
          }
        ],
        "id": "CVE-2026-98252",
        "lastModified": "2026-10-07T07:17:06.380",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.0,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.0,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:13.723",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/117871cdb8927542abd7b65ce5995bf0265a8c05"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/33fb59da49c4c3f5c2ec9f9d4447a56857a02c02"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/52c13c63bb3662c108244e7447055e30bf40244e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/88e429a4e9bac3d2138011c5ca06254331f2587f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/8a91609032d47e77bcb37bc8f6e88d89340d2709"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ce8a379598bd4058081416abea4279fd05a95374"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e15eb536be4f646ce683d2867572b2200be877f7"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:49:13Z",
      "cve": "CVE-2026-98252",
      "id": "CVE-2026-98252",
      "initial_release_date": "2026-10-08T16:49:13Z",
      "product_status:known_affected": "297",
      "product_status:known_not_affected": "50",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98252",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98252.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…