---
id: CVE-2026-98252
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

  iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
  making it accessible to global list where…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

  iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
  making it accessible to global list where…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    52c13c63bb3662c108244e7447055e30bf40244e
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    8a91609032d47e77bcb37bc8f6e88d89340d2709
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    ce8a379598bd4058081416abea4279fd05a95374
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    88e429a4e9bac3d2138011c5ca06254331f2587f
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    e15eb536be4f646ce683d2867572b2200be877f7
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    117871cdb8927542abd7b65ce5995bf0265a8c05
  - >-
    Linux >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 <
    33fb59da49c4c3f5c2ec9f9d4447a56857a02c02
  - Linux 3.16
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:13.723'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98252'
references:
  - url: 'https://git.kernel.org/stable/c/117871cdb8927542abd7b65ce5995bf0265a8c05'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/33fb59da49c4c3f5c2ec9f9d4447a56857a02c02'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/52c13c63bb3662c108244e7447055e30bf40244e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/88e429a4e9bac3d2138011c5ca06254331f2587f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8a91609032d47e77bcb37bc8f6e88d89340d2709'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce8a379598bd4058081416abea4279fd05a95374'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e15eb536be4f646ce683d2867572b2200be877f7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.430Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
making it accessible to global list where another CPU can kref_get()
on nlmsg_request causing a refcount "addition on 0" bug. Fix this
by initializing kref _before_ list_add_tail() so refcount for
nlmsg_request can be incremented/decremented normally. In addition,
also initialize every field before list_add_tail().

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
