Sceawere
Vulnerability Detail
CVE-2026-98361UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RDMA/rxe ODP Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages") dropped the access permission test from rxe_check_pagefault() and left only HMM_PFN_VALID. A page faulted in read-only, for example a page-cache folio behind a PROT_READ file mapping, then satisfies the check and ODP write operations (RDMA WRITE, RDMA READ response, SEND payload, atomics) modify it through kmap without ever breaking CoW. An unprivileged user can register an ODP MR over such a mapping and have incoming RDMA traffic overwrite the page cache of a file it only holds O_RDONLY, including /etc/passwd or setuid binaries. This is the same primitive class as Dirty COW and CVE-2022-2590. mlx5 has the missing invariant: its ODP path sets the device write bit only for pfns that carry HMM_PFN_WRITE. Restore it in rxe by requiring HMM_PFN_WRITE in rxe_check_pagefault() for every operation except RXE_PAGEFAULT_RDONLY. A write to a non-writable VMA now fails the one fault attempt with -EPERM from hmm_vma_fault() instead of re-faulting forever. For a writable VMA the fault breaks CoW and the write lands in the private page. Keep pmem flushes on the read-only check. arch_wb_cache_pmem() never modifies memory, and the FLUSH access bits do not make the umem writable, so classifying flushes as writes would make every flush against a flush-only MR fail.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:29.960Z",
"pubdate": "2026-10-06T09:18:29.960Z",
"executiveSummary": "A critical memory protection flaw exists in the Linux kernel RDMA/rxe component related to On-Demand Paging (ODP) write operations.\nThe vulnerability occurs due to the improper validation of page permissions when handling page faults, allowing an unprivileged attacker to bypass Copy-on-Write (CoW) protections.\nAn attacker can exploit this to perform unauthorized writes to read-only memory mappings, including page-cache folios of sensitive files like /etc/passwd or setuid binaries.\nThe risk is high, as it enables local privilege escalation (LPE) similar to the Dirty COW vulnerability (CVE-2022-2590).\nExploitation requires an unprivileged user to register an ODP Memory Region (MR) over a read-only mapping and trigger RDMA traffic. The vulnerability affects systems utilizing the Soft-RoCE (rxe) driver.",
"technicalDetails": "The root cause of this vulnerability lies in the incorrect handling of HMM (Heterogeneous Memory Management) PFN flags within the 'rxe_check_pagefault' function of the Linux kernel's RDMA/rxe driver. Specifically, the commit 0b261d7c1cd3 inadvertently removed the HMM_PFN_WRITE permission check, leaving only the HMM_PFN_VALID check.\nIn the ODP (On-Demand Paging) mechanism, the driver must verify if the memory region is writable before allowing the hardware or software-emulated RDMA operations to modify the underlying physical pages.\nBecause the write-permission check was missing, the RDMA/rxe subsystem treated pages mapped as read-only (such as file-backed pages in a PROT_READ mapping) as eligible for write operations. When an RDMA write operation is initiated, the system performs a kmap and modifies the page content directly without triggering the necessary CoW mechanism.\nThe exploitation flow involves the following steps: 1) The attacker creates a read-only file mapping (e.g., using mmap with PROT_READ). 2) The attacker registers an ODP Memory Region (MR) covering this mapping. 3) The attacker initiates an RDMA operation (such as RDMA WRITE, RDMA READ response, or SEND payload) that targets this memory region. 4) Because the driver fails to validate the HMM_PFN_WRITE flag, the 'rxe_check_pagefault' function erroneously approves the operation. 5) The kernel allows the RDMA engine to write to the page-cache folio via kmap. 6) The underlying file on the disk is modified, despite the attacker having only O_RDONLY access.\nThis behavior bypasses standard kernel memory protections, allowing an attacker to modify sensitive system files or executable binaries, leading to arbitrary code execution or local privilege escalation. This primitive is functionally equivalent to the Dirty COW vulnerability. The fix involves reinstating the HMM_PFN_WRITE check within 'rxe_check_pagefault' for all operations that are not explicitly marked as RXE_PAGEFAULT_RDONLY, ensuring that writes to non-writable VMAs fail with -EPERM instead of facilitating unauthorized page modification."
}