{"id":"CVE-2026-98360","summary":"RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe-\u003emcg_tree before programming the backing Ethernet multicast address\nwith rxe_mcast_add(), which runs outside mcg_lock. A local userspace\nRDMA client reaches this path with ATTACH_MCAST on a UD QP; if\nrxe_mcast_add() then returns an error (for example -ENODEV when the\nbacking netdev has been removed, or a propagated dev_mc_add() error),\nthe unwind frees the published group without removing it from the tree.\nA later lookup of the same MGID dereferences the freed struct rxe_mcg\nfrom __rxe_lookup_mcg().\n\nFix this by keeping the new mcg private until rxe_mcast_add() succeeds.\nSplit the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()\nbefore taking the tree reference, and free the still-private mcg on\nfailure. Because the group is never visible in mcg_tree until the\nmulticast address is programmed, no concurrent caller can look it up or\nattach a QP to a group that is about to be torn down, so the error path\nneeds no conditional unwind. If another caller publishes the same MGID\nwhile the address is being programmed, the post-add re-check under\nmcg_lock finds the winner; this caller then drops its private object and\nbalances its own rxe_mcast_add() with rxe_mcast_del() before returning\nthe winner.\n\nReproduced by forcing the rxe_mcast_add() error return under KASAN:\nwithout the change the next attach to the same MGID reports a\nslab-use-after-free in __rxe_lookup_mcg(); with it the forced failure\nreturns cleanly. A no-injection attach/detach regression, including a\ntwo-QP shared join/leave and re-attach, stays KASAN- and leak-clean.","modified":"2026-10-07T02:47:34.567734973Z","published":"2026-10-06T08:46:46.743Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98360.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/02c0a2fa69c16248a7432af8a6d64ab2a73a5283"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1caceeb2d74bbe88223aea55eb8626b4c5f076fd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c79a789aa15180a1543b5db49c343d12e3ec214d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d4fc4e37f8a143b0fe83b42c8fb48cf542154fee"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ddb43ac0926d4a931bc9b7744b93627f627457e5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/faae1fb4ccf8205806a8802c008798dabeb0205b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98360.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98360"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a926a903b7dc39a8a949150258c09290998dd812"},{"fixed":"ddb43ac0926d4a931bc9b7744b93627f627457e5"},{"fixed":"c79a789aa15180a1543b5db49c343d12e3ec214d"},{"fixed":"faae1fb4ccf8205806a8802c008798dabeb0205b"},{"fixed":"02c0a2fa69c16248a7432af8a6d64ab2a73a5283"},{"fixed":"d4fc4e37f8a143b0fe83b42c8fb48cf542154fee"},{"fixed":"1caceeb2d74bbe88223aea55eb8626b4c5f076fd"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98360.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.18.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98360.json"}}],"schema_version":"1.9.0"}