CVE-2026-98361
Received Received - Intake

RDMA Write Access in Linux Kernel via ODP Page Fault

Vulnerability report for CVE-2026-98361, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only HMM_PFN_VALID. A page faulted in read-only, for example a page-cache folio behind a PROT_READ file mapping, then satisfies the check and ODP write operations (RDMA WRITE, RDMA READ response, SEND payload, atomics) modify it through kmap without ever breaking CoW. An unprivileged user can register an ODP MR over such a mapping and have incoming RDMA traffic overwrite the page cache of a file it only holds O_RDONLY, including /etc/passwd or setuid binaries. This is the same primitive class as Dirty COW and CVE-2022-2590. mlx5 has the missing invariant: its ODP path sets the device write bit only for pfns that carry HMM_PFN_WRITE. Restore it in rxe by requiring HMM_PFN_WRITE in rxe_check_pagefault() for every operation except RXE_PAGEFAULT_RDONLY. A write to a non-writable VMA now fails the one fault attempt with -EPERM from hmm_vma_fault() instead of re-faulting forever. For a writable VMA the fault breaks CoW and the write lands in the private page. Keep pmem flushes on the read-only check. arch_wb_cache_pmem() never modifies memory, and the FLUSH access bits do not make the umem writable, so classifying flushes as writes would make every flush against a flush-only MR fail.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Linux Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638
Linux Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638
Linux Linux 0b261d7c1cd32dc93cbc92425fb55e67b24c6638
Linux Linux 6.16

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel allows an unprivileged user to register an On-Demand Paging (ODP) Memory Region (MR) over a read-only file mapping. Incoming RDMA traffic can then overwrite the page cache of files the user only has read access to, such as /etc/passwd or setuid binaries. This is similar to the Dirty COW vulnerability.

Detection Guidance

This vulnerability is specific to the Linux kernel's RDMA/rxe subsystem and requires kernel-level inspection. Detection involves checking kernel version and RDMA configuration. Use 'uname -r' to check kernel version and 'dmesg | grep rxe' to verify if the rxe driver is loaded. If vulnerable, the system may show repeated page faults or memory corruption issues in logs.

Impact Analysis

An attacker could exploit this to modify critical system files or binaries, leading to privilege escalation, data corruption, or denial of service. Systems using RDMA with the Linux kernel are at risk if the vulnerable code is present.

Compliance Impact

This vulnerability could lead to unauthorized data modification or access, violating integrity and confidentiality requirements in GDPR and HIPAA. Compliance may be compromised if systems are not patched.

Mitigation Strategies

Apply the latest kernel update from your distribution to patch the RDMA/rxe flaw. Disable RDMA functionality if not required by running 'systemctl stop rdma' and masking the service with 'systemctl mask rdma'. Monitor system logs for unusual page faults or memory corruption events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98361. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart