7.8

CVE-2026-98366

RDMA/rxe: validate access flags before swapping the MR's PD

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: validate access flags before swapping the MR's PD

rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then
validates the IB_MR_REREG_ACCESS argument:

	if (flags & IB_MR_REREG_PD) {
		rxe_put(old_pd);
		rxe_get(pd);
		mr->ibmr.pd = ibpd;
	}

	if (flags & IB_MR_REREG_ACCESS) {
		if (access & ~RXE_ACCESS_SUPPORTED_MR)
			return ERR_PTR(-EOPNOTSUPP);
		mr->access = access;
	}

Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is
IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.

mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error
without undoing the reassignment, so mr->pd == new_pd while the usecnts
still charge the MR to orig_pd. ib_dereg_mr_user() then decrements
new_pd, whose count can reach zero while a memory window still references
it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup()
writes to freed memory:

  BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0
  Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591
   __rxe_put+0x31/0xa0
   rxe_mw_cleanup+0x42/0x200
   __rxe_cleanup+0x115/0x370
   rxe_dealloc_mw+0x4c/0x80
  Allocated by task 591:
   ib_uverbs_alloc_pd+0x258/0x540
  Freed by task 591:
   ib_dealloc_pd_user+0x174/0x210
   uverbs_free_pd+0x8d/0xc0
   ib_uverbs_dealloc_pd+0x18e/0x1d0

Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Version < 08f12745cb72981aa2cabe214af0c7a42a856f0a
Status affected
Version 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Version < 7230cc456d4bb2221c20c5f1d22b38b8576aa16f
Status affected
Version 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Version < fe602c91a52e161ace4afd5bdb8f33270c554c6f
Status affected
Version 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Version < 4dd7a53f1c5b44693c26dac4b9b5bd5bb9d604c8
Status affected
Version 544c7f62cf32db2bd358f1e8a40a98bf98fa2a5c
Version < ae36a5b609ae79f4de966328b78d2584be9719a4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.015
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/08f12745cb72981aa2cabe214af0c7a42a856f0a
https://git.kernel.org/stable/c/7230cc456d4bb2221c20c5f1d22b38b8576aa16f
https://git.kernel.org/stable/c/fe602c91a52e161ace4afd5bdb8f33270c554c6f
https://git.kernel.org/stable/c/4dd7a53f1c5b44693c26dac4b9b5bd5bb9d604c8
https://git.kernel.org/stable/c/ae36a5b609ae79f4de966328b78d2584be9719a4