CVE-2026-98367: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98367 is a use-after-free (UAF) vulnerability in the Linux kernel's RDMA/siw (Software iWARP) subsystem, specifically in the siw_accept() function. It arises from a race condition when siw_qp_modify() fails and the connection endpoint (cep) association is not cleared under the state lock before it is released, allowing a concurrent ibv_modify_qp() call to free the cep while siw_accept() still holds a reference to it. The vulnerability affects Linux kernel versions from 5.3 (commit 6c52fdc244b5) up to the respective stable-branch fix commits. It was disclosed on October 6, 2026, with patches published to multiple stable branches. The CVSS base score is currently 0.0 (unscored), with Feedly estimating a MEDIUM severity (GitHub Advisory, Feedly).

Technical details

The root cause is a race condition (CWE-362) combined with a use-after-free memory error (CWE-416) in the siw_accept() function of the RDMA/siw kernel subsystem. When siw_qp_modify() fails, the function releases qp->state_lock before clearing qp->cep. A concurrent thread executing ibv_modify_qp() to transition the QP to ERROR state can acquire the lock in this window, call siw_cep_put(qp->cep) which frees the cep object, and set qp->cep = NULL. The original siw_accept() error path then writes cep->qp = NULL to the now-freed memory, constituting a UAF. The fix clears qp->cep and drops the association reference from siw_cep_get() while still holding the write lock, so the concurrent thread observes qp->cep == NULL and skips its own put (GitHub Advisory, Kernel Announce).

Impact

A local user with access to RDMA/ibv operations can trigger this race condition by concurrently invoking ibv_modify_qp() while siw_accept() encounters a failure on a queue pair, resulting in kernel memory corruption via use-after-free. Successful exploitation can lead to kernel code execution (privilege escalation to root) or a kernel panic causing denial of service. The impact is confined to systems with the RDMA/siw subsystem active and accessible to unprivileged or low-privileged local users (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires local access to a system with the RDMA/siw subsystem loaded and the ability to perform ibv operations, limiting the attack surface. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Prerequisite access: Obtain local user access on a Linux system with the siw RDMA kernel module loaded and RDMA/ibv device access granted to the user (e.g., via /dev/infiniband/ permissions or rdma group membership).
  2. Set up a queue pair: Use the libibverbs API to create a Queue Pair (QP) and a connection endpoint (cep) via the SoftIWARP interface, placing the QP in a state where siw_accept() can be invoked.
  3. Trigger siw_accept() failure: Initiate a connection accept operation that will cause siw_qp_modify() to fail internally (e.g., by manipulating connection parameters or resource limits), causing siw_accept() to release qp->state_lock before clearing qp->cep.
  4. Race with ibv_modify_qp(): In a concurrent thread, immediately call ibv_modify_qp() to transition the QP to the ERROR state. If the race window is hit, this thread acquires state_lock, calls siw_cep_put(qp->cep) freeing the cep, and sets qp->cep = NULL.
  5. Trigger UAF write: The original siw_accept() error path then writes cep->qp = NULL to the freed cep memory, corrupting kernel heap. This corruption can be leveraged for privilege escalation or to cause a kernel panic (GitHub Advisory, Feedly).

Indicators of compromise

  • Logs: Kernel oops or BUG messages in dmesg or /var/log/kern.log referencing siw_accept, siw_qp_modify, or siw_cep_put with use-after-free or null pointer dereference traces.
  • Logs: KASAN (Kernel Address Sanitizer) reports indicating a use-after-free in the rdma_siw or siw module, if KASAN is enabled on the kernel.
  • Process: Unexpected privilege escalation of a local process that previously had access to /dev/infiniband/ devices.
  • File System: Unusual loading or unloading of the siw kernel module (lsmod | grep siw) on systems that do not normally use SoftIWARP.
  • Network: Anomalous RDMA/iWARP connection attempts or repeated failed connection accept operations visible in RDMA subsystem statistics (rdma stat or /sys/class/infiniband/).

Mitigation and workarounds

Patches have been backported to multiple stable Linux kernel branches. Updated versions containing the fix include: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, and 7.3-rc4 / 7.2.8. Administrators should update to a patched kernel version as the primary remediation. As a workaround where immediate patching is not feasible, restrict access to RDMA/ibv devices to trusted users only (e.g., tighten permissions on /dev/infiniband/ and remove untrusted users from the rdma group), or unload the siw module if SoftIWARP is not required (modprobe -r siw) (GitHub Advisory, Feedly).

Additional resources


Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98370CRITICAL9
  • Linux Kernel logoLinux Kernel
  • linux-realtime
NoYesOct 06, 2026
CVE-2026-98369HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-gke
NoYesOct 06, 2026
CVE-2026-98368HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-gcp-7.0
NoYesOct 06, 2026
CVE-2026-98367HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules
NoYesOct 06, 2026
CVE-2026-98366HIGH7.8
  • Linux Kernel logoLinux Kernel
  • bpftool
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management