CVE-2026-98353
Received
Received - Intake
Deadlock in Linux Kernel RDMA/erdma QP CQ XArray Updates
Vulnerability report for CVE-2026-98353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
Locked QP and CQ lookups from EQ interrupts can deadlock with
create-path XArray updates. If an interrupt arrives while the create
path holds the plain xa_lock, the lookup spins forever trying to
acquire the same lock.
Use IRQ-safe XArray helpers for all QP and CQ create-path updates,
including the GSI QP store and error paths. Initialize both arrays with
XA_FLAGS_LOCK_IRQ so sleeping allocations preserve interrupt state.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 4545f355654d044d35a31cd01cc46f491a8a7c36 |
| Linux | Linux | 98df2aee1459ee1c62c70cbe9b370d2a532aea36 |
| Linux | Linux | 610ef81797bb4f709e8675c1d8d093bb9ccdcbd8 |
| Linux | Linux | c0a83f29a24c7e7f8516630848ef6db4c174deed |
| Linux | Linux | 05b8ca493dd02319bca93c640b259c2ba51ef321 |
| Linux | Linux | 1fc9c1933959d2776a1ce7bf424251b8b5b586cd |
| Linux | Linux | 6e32f84b63c054e09392153125d7202abab2d14b |
| Linux | Linux | ec987c0654651036dad6a42f7fa2a6d7c16a3687 |
| Linux | Linux | c92686867638cda954fdb2bdbac8a75e3aa6eaae |
| Linux | Linux | 7.2.6 |
| Linux | Linux | 6.1.188 |
| Linux | Linux | 6.6.157 |
| Linux | Linux | 6.12.110 |
| Linux | Linux | 6.18.52 |
| Linux | Linux | 7.3-rc1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |