Sceawere
Vulnerability Detail
CVE-2026-98253UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RDMA/ucma Race Condition Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Serialize join and leave on copy_to_user failure rdma_join_multicast() queues RoCE work that later reads the ucma_multicast through event->param.ud.private_data, then list_add()s the CMA multicast at the head of id_priv->mc_list. rdma_leave_multicast() matches only by sockaddr and destroys the first hit. ucma_process_join() used to drop ctx->mutex after a successful join and retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls with the same address can therefore insert a second CMA entry before the first thread's leave. leave then cancels the newer work and the older worker still dereferences the ucma_multicast that the first thread frees. Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and, on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join. Do not leave if join itself failed: that path never published this address on mc_list, and a leave-by-addr would destroy an earlier successful join.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:13.887Z",
"pubdate": "2026-10-06T09:18:13.887Z",
"executiveSummary": "A race condition vulnerability exists in the Linux kernel RDMA/ucma component related to the serialization of multicast join and leave operations. The issue stems from improper synchronization of the ctx->mutex lock during the join process, specifically when handling copy_to_user failures.\nThis vulnerability allows for a race between concurrent JOIN_MCAST calls for the same address, leading to incorrect state management of the id_priv->mc_list. An attacker capable of triggering concurrent join requests could cause the kernel to dereference memory that has already been freed (Use-After-Free) or perform unauthorized memory operations.\nThe vulnerability resides within the user-space RDMA Communication Manager (ucma) interface. Successful exploitation could lead to system instability, kernel panics, or potential local privilege escalation. There are no specific version numbers provided, but the issue impacts implementations where concurrent join/leave logic is not serialized correctly. The attack requires a local user with permissions to interact with the RDMA/ucma subsystem.",
"technicalDetails": "The root cause of this vulnerability is a race condition in ucma_process_join() where the ctx->mutex is prematurely released after a successful join and re-acquired only upon failure of the copy_to_user() operation. This lack of atomicity permits multiple concurrent JOIN_MCAST calls to overlap their execution flows.\nThe RDMA/ucma workflow involves queuing RoCE work that reads from a ucma_multicast structure via event->param.ud.private_data and subsequently performs a list_add() into the id_priv->mc_list. When two threads initiate JOIN_MCAST calls for the same multicast address concurrently, a scenario is created where a second CMA entry can be inserted into the list before the first thread has completed its cleanup or registration logic.\nThe exploitation flow proceeds as follows: First, Thread A initiates a join, and the operation proceeds to copy_to_user(). Due to the logic error, the mutex is dropped. Thread B then initiates an identical join request. Because the mutex is not held, Thread B proceeds, and the kernel potentially updates the multicast list incorrectly. If Thread A then hits an error condition (e.g., -EFAULT during copy_to_user), it initiates a leave operation via rdma_leave_multicast().\nrdma_leave_multicast() identifies targets for removal based on the sockaddr. It destroys the first entry matching the address found in the list. Because of the race, the leave operation may inadvertently target and destroy the newer, valid entry created by Thread B. Following this, the older worker thread, which is still processing the initial join request, attempts to dereference the now-freed ucma_multicast memory associated with the destroyed entry.\nThis interaction results in a classic Use-After-Free (UAF) condition within the kernel space. The vulnerable component is the ucma_process_join function which improperly handles mutex scope in error recovery paths. The vulnerability enables an attacker to influence internal list management, leading to memory corruption or undefined behavior when the kernel later references stale pointers in the asynchronous work queue.\nThe exposure is limited to local users who have the ability to interact with the RDMA stack, typically requiring device access permissions. The payload behavior is defined by the state machine mismatch between the join completion, the copy_to_user error status, and the subsequent invocation of the leave-by-addr logic, resulting in the corruption of the multicast management structures."
}