CVE-2026-98361 Overview
CVE-2026-98361 is a Linux kernel vulnerability in the RDMA Software RoCE (rxe) driver's On-Demand Paging (ODP) code path. A prior commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") removed the write-permission test from rxe_check_pagefault(), leaving only an HMM_PFN_VALID check. An unprivileged local user can register an ODP memory region over a read-only file mapping and use incoming RDMA traffic to overwrite page-cache contents. The flaw mirrors the Dirty COW class of issues and is tracked alongside CVE-2022-2590 as the same primitive.
Critical Impact
Local unprivileged users can overwrite read-only files, including /etc/passwd and setuid binaries, by directing RDMA write traffic through an ODP memory region, enabling privilege escalation.
Affected Products
- Linux kernel versions containing commit 0b261d7c1cd3 in the RDMA/rxe subsystem
- Systems with Software RoCE (rxe) enabled and ODP memory region support
- Distributions shipping the vulnerable rxe_check_pagefault() implementation
Discovery Timeline
- 2026-10-06 - CVE-2026-98361 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98361
Vulnerability Analysis
The Software RoCE driver (rxe) implements RDMA transport over standard Ethernet and relies on rxe_check_pagefault() to validate page-fault results from the Heterogeneous Memory Management (HMM) subsystem. After commit 0b261d7c1cd3, the function accepted any page returning HMM_PFN_VALID, including read-only page-cache folios backing PROT_READ file mappings.
When the driver then performs ODP write operations such as RDMA WRITE, RDMA READ response, SEND payload delivery, or atomics, it maps the page with kmap and writes directly to it. The Copy-on-Write (CoW) mechanism is never triggered because the write bypasses the normal mm page-fault path. The result is unauthorized modification of pages a process holds only O_RDONLY against.
The mlx5 driver already enforces the correct invariant by only setting the device write bit when HMM_PFN_WRITE is present. The fix ports the same requirement into rxe_check_pagefault().
Root Cause
The root cause is a missing permission check in rxe_check_pagefault(). The function only verified page validity (HMM_PFN_VALID) and did not require HMM_PFN_WRITE before allowing write-class operations against the returned PFN. This permitted writes to pages that HMM returned as read-only.
Attack Vector
An unprivileged local user with access to an rxe RDMA device registers an ODP memory region over a file mapped PROT_READ. Incoming RDMA WRITE, SEND, or atomic traffic to that region modifies the underlying page cache. Because the write never breaks CoW, the modification is visible to all readers of the file and persists in cache. Targets include /etc/passwd, PAM configuration, and setuid binaries, yielding local privilege escalation.
The vulnerability requires local access and low privileges. No user interaction is required. See the upstream fix in the Kernel Git Commit Fix for the restored HMM_PFN_WRITE check.
Detection Methods for CVE-2026-98361
Indicators of Compromise
- Unexpected modifications to read-only system files such as /etc/passwd, /etc/shadow, or PAM configuration files on hosts with rdma_rxe loaded.
- Processes without write permission to a file observed holding RDMA memory region registrations covering that file's page cache.
- Kernel log entries referencing rxe_check_pagefault faults on files mapped PROT_READ.
Detection Strategies
- Audit which processes load the rdma_rxe kernel module and create user-mode RDMA memory regions via ibv_reg_mr with ODP flags.
- Monitor file integrity on sensitive paths (/etc/, /usr/bin/, setuid binaries) using tools such as AIDE or auditd watch rules.
- Correlate RDMA verbs activity from unprivileged UIDs with subsequent authentication-related file changes.
Monitoring Recommendations
- Enable auditd rules on /etc/passwd, /etc/shadow, and setuid binary directories with -p wa to flag write and attribute changes.
- Log kernel module loads for rdma_rxe and ib_uverbs and alert on their presence on hosts that do not require Software RoCE.
- Forward kernel and audit telemetry to a centralized data lake for correlation of RDMA activity against sensitive file modifications.
How to Mitigate CVE-2026-98361
Immediate Actions Required
- Apply the upstream kernel patch that restores the HMM_PFN_WRITE check in rxe_check_pagefault() for all operations except RXE_PAGEFAULT_RDONLY.
- Where patching is delayed, unload the rdma_rxe module on systems that do not require Software RoCE: modprobe -r rdma_rxe.
- Restrict access to /dev/infiniband/* character devices to trusted users only.
Patch Information
The fix is available in the upstream Linux stable tree. Review the Kernel Git Commit Fix, the Kernel Git Commit Update, and the Kernel Git Commit Improvement. Update to a stable kernel release that includes these commits and consult your distribution's advisories for backport availability.
Workarounds
- Blacklist the rdma_rxe module on hosts that do not need Software RoCE by adding blacklist rdma_rxe to /etc/modprobe.d/.
- Remove membership in groups granting access to InfiniBand verbs devices for untrusted local users.
- Deploy mandatory access control (SELinux, AppArmor) policies that restrict ibv_reg_mr usage to approved service accounts.
# Disable Software RoCE where not required
sudo rmmod rdma_rxe
echo 'blacklist rdma_rxe' | sudo tee /etc/modprobe.d/disable-rxe.conf
sudo update-initramfs -u
# Restrict access to RDMA verbs devices
sudo chmod 0600 /dev/infiniband/uverbs*
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.