CVE-2026-98367 Overview
CVE-2026-98367 is a use-after-free vulnerability in the Linux kernel's Soft iWARP (siw) RDMA driver. The flaw lives in the siw_accept() connection acceptance path. When siw_qp_modify() fails, the queue pair (QP) state_lock is released before cleanup completes, opening a race window with a concurrent ibv_modify_qp() call transitioning the QP to the ERROR state. The racing thread can free the connection endpoint (cep) while siw_accept() still holds a reference, producing a use-after-free when the cleanup path dereferences cep->qp.
Critical Impact
A local user with RDMA access can trigger kernel memory corruption, enabling denial of service or local privilege escalation.
Affected Products
- Linux kernel builds compiling the CONFIG_RDMA_SIW (Soft iWARP) driver
- Multiple stable kernel branches referenced by the fix commits (030306b, 32cd87f, 9dcc0f4, ad50d19, bfdc744, df25847, e3f0390, f11e09f)
- Linux distributions shipping the vulnerable drivers/infiniband/sw/siw/siw_cm.c prior to the backported fix
Discovery Timeline
- 2026-10-06 - CVE-2026-98367 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98367
Vulnerability Analysis
The vulnerability resides in the Soft iWARP RDMA provider, which implements iWARP over TCP in software. The siw_accept() function completes an incoming RDMA connection by transitioning a QP from IDLE to an active state through siw_qp_modify(). On the failure path, the current code releases qp->state_lock before clearing the association between the QP and its connection endpoint (cep).
Another thread calling ibv_modify_qp() with target state ERROR can acquire state_lock immediately after the release. The error transition executes nextstate_from_idle(), which observes a non-NULL qp->cep, invokes siw_cep_put(qp->cep) to drop the reference, and sets qp->cep = NULL. If this reference was the last, the cep object is freed.
Control then returns to siw_accept(), which executes cep->qp = NULL on the now-freed object. This write constitutes a classic use-after-free of kernel heap memory.
Root Cause
The root cause is improper lock scope. The cleanup of the qp->cep association and the matching reference drop must occur under the same write-held state_lock acquired at the start of siw_accept(). Dropping the lock before cleanup violates the invariant that association state changes are serialized against QP state transitions.
Attack Vector
Exploitation requires local access and permission to open RDMA devices (typically membership in a group with /dev/infiniband/* access). An attacker races two threads: one issuing an siw_accept() call that will fail inside siw_qp_modify(), and another concurrently calling ibv_modify_qp() to transition the same QP to ERROR. Winning the race corrupts freed slab memory, which can be shaped into denial of service or, with heap grooming, local privilege escalation.
No verified public exploit code is available. The upstream patch narrative in the kernel commits documents the race ordering.
Detection Methods for CVE-2026-98367
Indicators of Compromise
- Kernel oops or KASAN: use-after-free reports referencing siw_accept, siw_cep_put, or nextstate_from_idle in the stack trace
- Unexpected kernel panics on hosts loading the siw module after RDMA activity from unprivileged users
- dmesg entries showing repeated QP state transition failures correlated with ibv_modify_qp ERROR calls
Detection Strategies
- Enable KASAN on test and staging kernels to surface the use-after-free deterministically during RDMA fuzzing
- Audit which processes open /dev/infiniband/uverbs* and rdma_cm devices, since local RDMA access is required
- Track loaded kernel modules and alert when siw is loaded on hosts that do not require Soft iWARP
Monitoring Recommendations
- Forward dmesg and /var/log/kern.log to a centralized log store and alert on BUG:, KASAN, or general protection fault entries naming siw_* symbols
- Monitor kernel version drift across the fleet and flag hosts running pre-patch stable kernels
- Baseline RDMA syscall usage per user and alert on anomalous concurrent ibv_modify_qp activity targeting the same QP handle
How to Mitigate CVE-2026-98367
Immediate Actions Required
- Apply the upstream kernel patches referenced by commits 030306b, 32cd87f, 9dcc0f4, ad50d19, bfdc744, df25847, e3f0390, and f11e09f through your distribution's stable kernel update
- If Soft iWARP is not in use, blacklist the siw module to remove the attack surface entirely
- Restrict access to /dev/infiniband/* device nodes to trusted users and services only
Patch Information
The fix clears qp->cep and drops the association reference acquired by siw_cep_get() while the write lock from the initial down_write(&qp->state_lock) is still held. With this ordering, a racing thread entering nextstate_from_idle() observes qp->cep == NULL, skips its own siw_cep_put(), and cannot free the cep before siw_accept() finishes using it. See the Kernel Git Commit 030306b and Kernel Git Commit f11e09f for the reference fixes across stable branches.
Workarounds
- Unload and blacklist the siw module on systems that do not require software iWARP RDMA
- Limit RDMA device access to a dedicated group and remove unprivileged users from it
- Restrict container and VM workloads from exposing /dev/infiniband into untrusted guests
# Disable the Soft iWARP driver until patched kernels are deployed
sudo rmmod siw 2>/dev/null
echo 'blacklist siw' | sudo tee /etc/modprobe.d/blacklist-siw.conf
sudo update-initramfs -u
# Restrict RDMA device access
sudo chgrp rdma /dev/infiniband/*
sudo chmod 0660 /dev/infiniband/*
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.