GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel RDMA/siw: failed QP modify in siw_accept() races QP-to-ERROR transition into a use-after-free

CVSS 7.8CVE-2026-98367Kernel, userspace & hypervisorcurated

Impact

When siw_qp_modify() fails inside siw_accept(), the QP's state_lock is dropped before the error-path cleanup runs. A concurrent ibv_modify_qp() moving the QP to ERROR can slip into that window, put the connection endpoint and NULL qp->cep, after which siw_accept()'s error path writes through the freed cep. The result is kernel memory corruption driven from unprivileged userspace on any host running the software iWARP driver. On a multi-tenant GPU node this is a local escalation and crash primitive in a driver most operators do not realise is loaded; the fix clears qp->cep and drops the association reference while still holding the write lock.

Who can reach it

Local user with access to the RDMA uverbs devices, racing a connection accept against a QP state change. Requires the siw driver to be loaded; not remotely triggerable on its own.

What to do

Pick up the stable kernel fix (five stable commits listed) and reboot each node. Hosts that do not need software iWARP can blacklist or unload the siw module instead, which removes the attack surface without waiting for a kernel rollout. The record names no fixed release version.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.