CVE-2026-98354 is a vulnerability in Linux Kernel
Published on October 6, 2026
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
In the Linux kernel, the following vulnerability has been resolved:
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs
ib_mad_enforce_security() before linking recv_buf onto that list. On
failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees
the ib_mad_private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL
right after ib_mad_complete_recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv_buf onto rmpp_list right after the list is initialized, so the
error path has something to free.
Products Associated with CVE-2026-98354
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 4617c9a856188674dddb0ca66979746d07688579 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 8e2036fb47a5b152d53eadbd35abf311bd34cc7f is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below bad289e42f512646a988f278f536d21547df73f1 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 752b30e9d339008e5ce7eed412e9446078916129 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 39c4ea72a40503e102ae07e6776005f96ca078a6 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 5091e25ec503f7fc02723ca435226467b68caac7 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below c0d8df85db146d6275e226cb950023be69dd6c77 is affected.
- Version 47a2b338fe63200d716d2e24131cdb49f17c77da and below 3476c28c9addfa253f505e6bd87f1f5598b961d0 is affected.
- Version 4.13 is affected.
- Before 4.13 is unaffected.
- Version 5.10.271, <= 5.10.* is unaffected.
- Version 5.15.222, <= 5.15.* is unaffected.
- Version 6.1.189, <= 6.1.* is unaffected.
- Version 6.6.158, <= 6.6.* is unaffected.
- Version 6.12.112, <= 6.12.* is unaffected.
- Version 6.18.54, <= 6.18.* is unaffected.
- Version 7.2.8, <= 7.2.* is unaffected.
- Version 7.3-rc4, <= * is unaffected.