{"id":"CVE-2026-98360","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe->mcg_tree before programming th…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe->mcg_tree before programming th…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= a926a903b7dc39a8a949150258c09290998dd812 < ddb43ac0926d4a931bc9b7744b93627f627457e5","Linux >= a926a903b7dc39a8a949150258c09290998dd812 < c79a789aa15180a1543b5db49c343d12e3ec214d","Linux >= a926a903b7dc39a8a949150258c09290998dd812 < faae1fb4ccf8205806a8802c008798dabeb0205b","Linux >= a926a903b7dc39a8a949150258c09290998dd812 < 02c0a2fa69c16248a7432af8a6d64ab2a73a5283","Linux >= a926a903b7dc39a8a949150258c09290998dd812 < d4fc4e37f8a143b0fe83b42c8fb48cf542154fee","Linux >= a926a903b7dc39a8a949150258c09290998dd812 < 1caceeb2d74bbe88223aea55eb8626b4c5f076fd","Linux 5.18"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:29.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98360","references":[{"url":"https://git.kernel.org/stable/c/02c0a2fa69c16248a7432af8a6d64ab2a73a5283","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1caceeb2d74bbe88223aea55eb8626b4c5f076fd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c79a789aa15180a1543b5db49c343d12e3ec214d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4fc4e37f8a143b0fe83b42c8fb48cf542154fee","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddb43ac0926d4a931bc9b7744b93627f627457e5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/faae1fb4ccf8205806a8802c008798dabeb0205b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.392Z","slug":"CVE-2026-98360","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe->mcg_tree before programming the backing Ethernet multicast address\nwith rxe_mcast_add(), which runs outside mcg_lock. A local userspace\nRDMA client reaches this path with ATTACH_MCAST on a UD QP; if\nrxe_mcast_add() then returns an error (for example -ENODEV when the\nbacking netdev has been removed, or a propagated dev_mc_add() error),\nthe unwind frees the published group without removing it from the tree.\nA later lookup of the same MGID dereferences the freed struct rxe_mcg\nfrom __rxe_lookup_mcg().\n\nFix this by keeping the new mcg private until rxe_mcast_add() succeeds.\nSplit the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()\nbefore taking the tree reference, and free the still-private mcg on\nfailure. Because the group is never visible in mcg_tree until the\nmulticast address is programmed, no concurrent caller can look it up or\nattach a QP to a group that is about to be torn down, so the error path\nneeds no conditional unwind. If another caller publishes the same MGID\nwhile the address is being programmed, the post-add re-check under\nmcg_lock finds the winner; this caller then drops its private object and\nbalances its own rxe_mcast_add() with rxe_mcast_del() before returning\nthe winner.\n\nReproduced by forcing the rxe_mcast_add() error return under KASAN:\nwithout the change the next attach to the same MGID reports a\nslab-use-after-free in __rxe_lookup_mcg(); with it the forced failure\nreturns cleanly. A no-injection attach/detach regression, including a\ntwo-QP shared join/leave and re-attach, stays KASAN- and leak-clean.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}