CVE-2026-98366: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98366 is a use-after-free vulnerability in the Linux kernel's RDMA/rxe (Soft RoCE) subsystem, specifically in the rxe_rereg_user_mr() function responsible for memory region re-registration. The flaw arises because the function reassigns the memory region's Protection Domain (PD) before validating access flags, leaving reference counts in an inconsistent state on error paths. The vulnerability was published on October 6, 2026, and affects Linux kernel versions starting from 6.5 up to the patched stable releases (GitHub Advisory). Fixed versions include 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4. The CVSS category is estimated as High (Feedly).

Technical details

The root cause is a logic ordering error (CWE class: Use-After-Free) in rxe_rereg_user_mr() within the Linux kernel RDMA/rxe driver. When both IB_MR_REREG_PD and IB_MR_REREG_ACCESS flags are set, the function first swaps mr->ibmr.pd to the new PD (decrementing the old PD's refcount and incrementing the new one), and only then validates the access flags. If the access flag check fails and returns ERR_PTR(-EOPNOTSUPP), the error path in ib_uverbs_rereg_mr() does not undo the PD reassignment — it jumps to put_new_uobj without restoring mr->ibmr.pd. This leaves the MR pointing to the new PD while usage counts still attribute it to the original PD. Subsequently, ib_dereg_mr_user() decrements the new PD's refcount, which can reach zero while memory windows still reference it; uverbs_free_pd() then frees the PD, and rxe_mw_cleanup() writes to the freed memory, triggering a KASAN slab-use-after-free at __rxe_put+0x31/0xa0 (GitHub Advisory). The fix reorders validation to check access flags before any state mutation, ensuring atomicity of the re-registration operation.

Impact

Successful exploitation allows a local user with RDMA permissions to trigger a use-after-free write in kernel memory, potentially enabling arbitrary kernel code execution with elevated privileges. The vulnerability affects the confidentiality, integrity, and availability of the system — an attacker could escalate privileges, corrupt kernel data structures, or crash the system. The scope is limited to systems with RDMA/rxe (Soft RoCE) enabled and accessible to unprivileged or semi-privileged local users (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires local access and permissions to perform RDMA memory region operations, significantly limiting the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. No EPSS score is currently available for this CVE.

Exploitation steps

  1. Gain local access: Obtain a local account on a Linux system with the RDMA/rxe (Soft RoCE) subsystem enabled and with user-level RDMA permissions (e.g., membership in the rdma group or equivalent).
  2. Allocate resources: Using the IB uverbs interface, allocate two Protection Domains (orig_pd and new_pd) and register a Memory Region (MR) under orig_pd. Also allocate a Memory Window (MW) referencing the MR.
  3. Trigger the vulnerable code path: Call ibv_rereg_mr() (or the equivalent uverbs ioctl) with both IBV_REREG_MR_CHANGE_PD and IBV_REREG_MR_CHANGE_ACCESS flags set, specifying new_pd and an unsupported access flag value (one that sets bits outside RXE_ACCESS_SUPPORTED_MR).
  4. Induce the inconsistent state: The kernel swaps mr->ibmr.pd to new_pd, then fails the access flag check and returns an error — but does not undo the PD swap. The MR now points to new_pd while refcounts still charge orig_pd.
  5. Trigger use-after-free: Deregister the MR (ibv_dereg_mr()). The kernel decrements new_pd's refcount to zero and frees it via uverbs_free_pd(), while the MW still holds a reference. Any subsequent MW cleanup (rxe_mw_cleanup()) writes to the freed PD memory, achieving a kernel use-after-free write that can be leveraged for privilege escalation (GitHub Advisory).

Indicators of compromise

  • Logs: Kernel logs (dmesg) showing BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0 with a write to a freed address by a process named rxe_poc or similar; stack traces involving rxe_mw_cleanup, __rxe_cleanup, rxe_dealloc_mw, and ib_dealloc_pd_user.
  • Process: Unusual processes invoking RDMA uverbs operations (ibv_rereg_mr, ibv_dereg_mr) in rapid succession, particularly from non-standard user accounts.
  • File System: Presence of RDMA test or PoC binaries (e.g., named rxe_poc) in user home directories or /tmp.
  • Kernel: Kernel panic or system instability following RDMA memory region re-registration operations on systems with Soft RoCE enabled (GitHub Advisory).

Mitigation and workarounds

Apply the kernel patches that reorder access flag validation to occur before any PD state mutation in rxe_rereg_user_mr(). Fixed stable kernel versions are 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4 (GitHub Advisory). Patch commits are available at the kernel stable tree (commits 08f12745, 7230cc45, fe602c91, 4dd7a53f, ae36a5b6). As a workaround until patching is possible, restrict RDMA operations to trusted users only by tightening access controls on the /dev/infiniband/ uverbs devices or disabling the rxe module (modprobe -r rdma_rxe) if Soft RoCE is not required.

Additional resources


Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98370CRITICAL9
  • Linux Kernel logoLinux Kernel
  • linux-realtime
NoYesOct 06, 2026
CVE-2026-98369HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-gke
NoYesOct 06, 2026
CVE-2026-98368HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-gcp-7.0
NoYesOct 06, 2026
CVE-2026-98367HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules
NoYesOct 06, 2026
CVE-2026-98366HIGH7.8
  • Linux Kernel logoLinux Kernel
  • bpftool
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management