CVE-2026-98354
Received Received - Intake

Memory Leak in Linux Kernel RDMA/MAD

Vulnerability report for CVE-2026-98354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Fix receive buffer leak when PKey enforcement fails ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs ib_mad_enforce_security() before linking recv_buf onto that list. On failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees the ib_mad_private of every buffer found there. As the list is still empty at that point, nothing is freed at all. The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL right after ib_mad_complete_recv() returns, assuming the MAD layer took ownership of the buffer. Every MAD that fails the PKey check therefore leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA), and a remote node can trigger this repeatedly by sending MADs with a wrong PKey. Link recv_buf onto rmpp_list right after the list is initialized, so the error path has something to free.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 47a2b338fe63200d716d2e24131cdb49f17c77da
Linux Linux 4.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a memory leak in the RDMA (Remote Direct Memory Access) MAD (Management Datagram) layer. When PKey (Partition Key) enforcement fails, the system fails to properly free allocated memory buffers, causing a leak of about 300 bytes per IB port MAD or around 2KB for OPA.

Detection Guidance

This vulnerability is specific to the Linux kernel's RDMA/mad subsystem and may not have direct detection commands. Monitor for memory leaks in RDMA-related processes or kernel logs for PKey enforcement failures. Check kernel logs with 'dmesg | grep -i mad' or 'journalctl -k | grep -i mad'.

Impact Analysis

An attacker could exploit this by sending malicious MADs with incorrect PKeys, repeatedly triggering the memory leak. This could lead to resource exhaustion on the affected system, potentially causing performance degradation or system instability over time.

Mitigation Strategies

Apply the latest Linux kernel patches to resolve the issue. If immediate patching is not possible, disable RDMA/mad services if unused or restrict network access to RDMA ports. Monitor system memory usage for leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98354. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart