
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98367 is a use-after-free (UAF) vulnerability in the Linux kernel's RDMA/siw (Software iWARP) subsystem, specifically in the siw_accept() function. It arises from a race condition when siw_qp_modify() fails and the connection endpoint (cep) association is not cleared under the state lock before it is released, allowing a concurrent ibv_modify_qp() call to free the cep while siw_accept() still holds a reference to it. The vulnerability affects Linux kernel versions from 5.3 (commit 6c52fdc244b5) up to the respective stable-branch fix commits. It was disclosed on October 6, 2026, with patches published to multiple stable branches. The CVSS base score is currently 0.0 (unscored), with Feedly estimating a MEDIUM severity (GitHub Advisory, Feedly).
The root cause is a race condition (CWE-362) combined with a use-after-free memory error (CWE-416) in the siw_accept() function of the RDMA/siw kernel subsystem. When siw_qp_modify() fails, the function releases qp->state_lock before clearing qp->cep. A concurrent thread executing ibv_modify_qp() to transition the QP to ERROR state can acquire the lock in this window, call siw_cep_put(qp->cep) which frees the cep object, and set qp->cep = NULL. The original siw_accept() error path then writes cep->qp = NULL to the now-freed memory, constituting a UAF. The fix clears qp->cep and drops the association reference from siw_cep_get() while still holding the write lock, so the concurrent thread observes qp->cep == NULL and skips its own put (GitHub Advisory, Kernel Announce).
A local user with access to RDMA/ibv operations can trigger this race condition by concurrently invoking ibv_modify_qp() while siw_accept() encounters a failure on a queue pair, resulting in kernel memory corruption via use-after-free. Successful exploitation can lead to kernel code execution (privilege escalation to root) or a kernel panic causing denial of service. The impact is confined to systems with the RDMA/siw subsystem active and accessible to unprivileged or low-privileged local users (Feedly, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires local access to a system with the RDMA/siw subsystem loaded and the ability to perform ibv operations, limiting the attack surface. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.
siw RDMA kernel module loaded and RDMA/ibv device access granted to the user (e.g., via /dev/infiniband/ permissions or rdma group membership).siw_accept() can be invoked.siw_qp_modify() to fail internally (e.g., by manipulating connection parameters or resource limits), causing siw_accept() to release qp->state_lock before clearing qp->cep.ibv_modify_qp() to transition the QP to the ERROR state. If the race window is hit, this thread acquires state_lock, calls siw_cep_put(qp->cep) freeing the cep, and sets qp->cep = NULL.siw_accept() error path then writes cep->qp = NULL to the freed cep memory, corrupting kernel heap. This corruption can be leveraged for privilege escalation or to cause a kernel panic (GitHub Advisory, Feedly).dmesg or /var/log/kern.log referencing siw_accept, siw_qp_modify, or siw_cep_put with use-after-free or null pointer dereference traces.rdma_siw or siw module, if KASAN is enabled on the kernel./dev/infiniband/ devices.siw kernel module (lsmod | grep siw) on systems that do not normally use SoftIWARP.rdma stat or /sys/class/infiniband/).Patches have been backported to multiple stable Linux kernel branches. Updated versions containing the fix include: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, and 7.3-rc4 / 7.2.8. Administrators should update to a patched kernel version as the primary remediation. As a workaround where immediate patching is not feasible, restrict access to RDMA/ibv devices to trusted users only (e.g., tighten permissions on /dev/infiniband/ and remove untrusted users from the rdma group), or unload the siw module if SoftIWARP is not required (modprobe -r siw) (GitHub Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."