CVE-2026-98353: RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
In the Linux kernel, the following vulnerability has been resolved:
RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
Locked QP and CQ lookups from EQ interrupts can deadlock with create-path XArray updates. If an interrupt arrives while the create path holds the plain xalock, the lookup spins forever trying to acquire the same lock.
Use IRQ-safe XArray helpers for all QP and CQ create-path updates, including the GSI QP store and error paths. Initialize both arrays with XAFLAGSLOCKIRQ so sleeping allocations preserve interrupt state.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Initialize both QP and CQ XArrays with XA_FLAGS_LOCK_IRQ and use IRQ-safe XArray helpers for all create-path updates, including the GSI QP store and error paths.
RDMA/erdma QP and CQ XArray tables XA_FLAGS_LOCK_IRQ = enabled
Event History
Frequently Asked Questions
What conditions are required to trigger the deadlock?
An EQ interrupt must arrive while the ERDMA create path is updating the QP or CQ XArray while holding the plain xa_lock. The interrupt-side lookup can then spin indefinitely attempting to acquire that same lock.
Which ERDMA operations need IRQ-safe handling?
The affected updates are QP and CQ create-path XArray updates, including the GSI QP store and associated error paths. Both arrays need IRQ-safe locking initialization so allocations preserve interrupt state.
What is the operational impact if the issue is triggered?
The QP or CQ lookup performed from the EQ interrupt context can deadlock, causing it to spin forever on the XArray lock.