CVE-2026-98253: RDMA/ucma: Serialize join and leave on copy_to_user failure

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

RDMA/ucma: Serialize join and leave on copytouser failure

rdmajoinmulticast() queues RoCE work that later reads the ucmamulticast through event->param.ud.privatedata, then listadd()s the CMA multicast at the head of idpriv->mclist. rdmaleavemulticast() matches only by sockaddr and destroys the first hit.

ucmaprocessjoin() used to drop ctx->mutex after a successful join and retake it only if copytouser() failed. Two concurrent JOINMCAST calls with the same address can therefore insert a second CMA entry before the first thread's leave. leave then cancels the newer work and the older worker still dereferences the ucmamulticast that the first thread frees.

Keep ctx->mutex held from rdmajoinmulticast() through copytouser() and, on -EFAULT, through rdmaleavemulticast() so leave cannot miss this join. Do not leave if join itself failed: that path never published this address on mclist, and a leave-by-addr would destroy an earlier successful join.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Keep ctx->mutex held from rdma_join_multicast() through copy_to_user(), and serialize JOIN_MCAST and leave operations so that a leave cannot cancel or destroy an in-progress join when copy_to_user() fails.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverity
Data Sourced
via NVD·09:18 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:14 AM
DescriptionSeverityWeakness
Sep 6, 58736
Event
via FIRST·07:15 PM

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Exploitation requires local access and low privileges, according to the CVSS vector. The vulnerable path is in the Linux kernel RDMA/ucma multicast join and leave handling.

2

What conditions are needed to trigger the race?

Two concurrent JOIN_MCAST operations using the same address must allow a second CMA multicast entry to be inserted before the first operation performs its leave. The problematic cleanup path is reached when copy_to_user() fails after a successful join.

3

What is the impact of a successful trigger?

The leave operation can cancel the newer multicast work while an older worker still references ucma_multicast data freed by the first thread. This creates a use-after-free condition with high confidentiality, integrity, and availability impact in the CVSS assessment.

4

What does the fix change?

The fix holds ctx->mutex from rdma_join_multicast() through copy_to_user(), and through rdma_leave_multicast() when copy_to_user() returns -EFAULT. It also avoids issuing a leave when the join itself failed, because that could remove an earlier successful join for the same address.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203