{"id":"CVE-2026-98353","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables\n\nLocked QP and CQ lookups from EQ interrupts can deadlock with\ncreate-path XArray updates","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables\n\nLocked QP and CQ lookups from EQ interrupts can deadlock with\ncreate-path XArray updates. If an interrupt …","severity":"medium","vendor":"Linux","product":"Linux","affected":["Linux >= 4545f355654d044d35a31cd01cc46f491a8a7c36 < 74d4085221a7ec5440996af199ccadfa75b9eb0e","Linux >= 98df2aee1459ee1c62c70cbe9b370d2a532aea36 < 00baeade709fb66da647e8327e8398bb532e30f7","Linux 610ef81797bb4f709e8675c1d8d093bb9ccdcbd8","Linux c0a83f29a24c7e7f8516630848ef6db4c174deed","Linux 05b8ca493dd02319bca93c640b259c2ba51ef321","Linux 1fc9c1933959d2776a1ce7bf424251b8b5b586cd","Linux 6e32f84b63c054e09392153125d7202abab2d14b","Linux ec987c0654651036dad6a42f7fa2a6d7c16a3687","Linux c92686867638cda954fdb2bdbac8a75e3aa6eaae","Linux >= 7.2.6 < 7.2.8","Linux >= 6.1.188 < 6.2","Linux >= 6.6.157 < 6.7","Linux >= 6.12.110 < 6.13","Linux >= 6.18.52 < 6.19","Linux 7.3-rc1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:28.750","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98353","references":[{"url":"https://git.kernel.org/stable/c/00baeade709fb66da647e8327e8398bb532e30f7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74d4085221a7ec5440996af199ccadfa75b9eb0e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98353.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-98353"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2546463"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98353"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98353"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-98353.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-10-06T08:50:17.396Z","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-833"],"slug":"CVE-2026-98353","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables\n\nLocked QP and CQ lookups from EQ interrupts can deadlock with\ncreate-path XArray updates. If an interrupt arrives while the create\npath holds the plain xa_lock, the lookup spins forever trying to\nacquire the same lock.\n\nUse IRQ-safe XArray helpers for all QP and CQ create-path updates,\nincluding the GSI QP store and error paths. Initialize both arrays with\nXA_FLAGS_LOCK_IRQ so sleeping allocations preserve interrupt state.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-10-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98353.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217095,"id":"CVE-2026-98353","ts":1791360669475,"field":"cvss","old":null,"new":"5.5"},{"seq":217094,"id":"CVE-2026-98353","ts":1791360669475,"field":"severity","old":"none","new":"medium"}]}