Sceawere

Vulnerability Detail

CVE-2026-98252UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel RDMA Use-After-Free

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref _before_ list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-10-06T09:18:13.723Z",
  "pubdate": "2026-10-06T09:18:13.723Z",
  "executiveSummary": "This vulnerability is a race condition in the Linux kernel RDMA subsystem that leads to a reference count underflow or 'addition on zero' bug.\nThe issue exists within the iwpm_get_nlmsg_request() function, which handles Netlink message requests.\nThe vulnerability allows for potential use-after-free conditions or memory corruption, as the object is exposed to a global list before its reference counter is properly initialized.\nAn attacker capable of triggering concurrent Netlink operations could potentially exploit this race condition to induce kernel memory instability or escalate privileges.\nThe flaw affects the RDMA core infrastructure, specifically impacting the lifecycle management of nlmsg_request objects.\nThis is a high-severity concurrency flaw that requires precise timing, but it poses significant risks to system stability and security integrity in environments relying on RDMA network acceleration.",
  "technicalDetails": "The root cause of this vulnerability is an improper order of operations within the iwpm_get_nlmsg_request() function in the Linux kernel RDMA core. The function creates and initializes an nlmsg_request object to track Netlink message states.\nIn the vulnerable implementation, the object is added to a global tracking list via list_add_tail() before the kref (reference counter) structure is initialized. By performing the list insertion prior to kref_init(), the object becomes visible and reachable by other kernel threads and concurrent processes while its internal state is still indeterminate.\nThe attack flow occurs through a race condition: 1) Thread A enters iwpm_get_nlmsg_request(), allocates the object, and executes list_add_tail(). 2) Before Thread A executes kref_init(), Thread B triggers an operation that iterates over the global list and identifies the newly created, but uninitialized, nlmsg_request object. 3) Thread B attempts to increment the object's reference count using kref_get(). 4) Because the refcount has not yet been set to its initial value (effectively remaining at zero or undefined), the kref_get() operation triggers a refcount 'addition on 0' bug.\nThis behavior violates the kref API safety requirements, which dictate that an object must be fully constructed and have a non-zero reference count before being published to any shared structures or lists. Exploitation of this race condition can lead to kernel-level memory corruption, as the system may prematurely free the object while other threads still possess references, or conversely, leak memory if the counter never reaches zero due to the corrupted initial state.\nBecause the RDMA core handles specialized networking traffic, this flaw is particularly dangerous for systems leveraging iWARP (Internet Wide-area RDMA Protocol). The vulnerability resides strictly in the kernel memory management of Netlink requests, and while exploitation requires the ability to trigger RDMA-related Netlink traffic, it does not necessarily require highly elevated privileges depending on the system configuration and the exposure of the RDMA management interface to user-space applications."
}
CVE-2026-98252: Linux Kernel RDMA Use-After-Free (HIGH Severity, CVSS: 7.0) | Sceawere