CVE-2026-98253
Received Received - Intake

Race Condition in Linux Kernel RDMA/ucma Component

Vulnerability report for CVE-2026-98253, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Serialize join and leave on copy_to_user failure rdma_join_multicast() queues RoCE work that later reads the ucma_multicast through event->param.ud.private_data, then list_add()s the CMA multicast at the head of id_priv->mc_list. rdma_leave_multicast() matches only by sockaddr and destroys the first hit. ucma_process_join() used to drop ctx->mutex after a successful join and retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls with the same address can therefore insert a second CMA entry before the first thread's leave. leave then cancels the newer work and the older worker still dereferences the ucma_multicast that the first thread frees. Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and, on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join. Do not leave if join itself failed: that path never published this address on mc_list, and a leave-by-addr would destroy an earlier successful join.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
Linux Linux 60d613b39e8d0c9f3b526e9c96445422b4562d76
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux fe454dc31e84f8c14cb8942fcb61666c9f40745b
Linux Linux a3262b3884dd67b4c5632ce7cdf9cff9d1a575d4
Linux Linux 5.10.20
Linux Linux 5.11.3
Linux Linux 5.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98253. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart