{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "60d613b39e8d0c9f3b526e9c96445422b4562d76"
            },
            {
              "fixed": "29b9ed83d8bfab5c6e11fcbf1aa836aa4ae26cb9"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "fe454dc31e84f8c14cb8942fcb61666c9f40745b"
            },
            {
              "fixed": "52172e11bd074ccaded21740ffeb67123f01dd00"
            },
            {
              "fixed": "01e29d0d78a8f66f221625720a04939eef5ec1f6"
            },
            {
              "fixed": "ae805d204cf1f15b87d1bf3529b4c649f3519420"
            },
            {
              "fixed": "43c4e24bd10370fc976f6220518049ce71419399"
            },
            {
              "fixed": "01cbdb724c584d7772fd25af2e4dfdf8527ce0d5"
            },
            {
              "fixed": "83610ee5e498fa5bfcb80031d2b959baea276bf6"
            },
            {
              "fixed": "662ade4de9ff5eceb0820a9f8e9fac70ba6a815b"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.10.20"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.11.3"
            },
            {
              "fixed": "5.12"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "a3262b3884dd67b4c5632ce7cdf9cff9d1a575d4"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.222"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.12.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98253.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Serialize join and leave on copy_to_user failure\n\nrdma_join_multicast() queues RoCE work that later reads the ucma_multicast\nthrough event-\u003eparam.ud.private_data, then list_add()s the CMA multicast\nat the head of id_priv-\u003emc_list. rdma_leave_multicast() matches only by\nsockaddr and destroys the first hit.\n\nucma_process_join() used to drop ctx-\u003emutex after a successful join and\nretake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls\nwith the same address can therefore insert a second CMA entry before the\nfirst thread's leave. leave then cancels the newer work and the older\nworker still dereferences the ucma_multicast that the first thread frees.\n\nKeep ctx-\u003emutex held from rdma_join_multicast() through copy_to_user() and,\non -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.\nDo not leave if join itself failed: that path never published this address\non mc_list, and a leave-by-addr would destroy an earlier successful join.",
  "id": "CVE-2026-98253",
  "modified": "2026-10-09T02:30:49.219914993Z",
  "published": "2026-10-06T08:45:20.077Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/01cbdb724c584d7772fd25af2e4dfdf8527ce0d5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/01e29d0d78a8f66f221625720a04939eef5ec1f6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/29b9ed83d8bfab5c6e11fcbf1aa836aa4ae26cb9"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/43c4e24bd10370fc976f6220518049ce71419399"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/52172e11bd074ccaded21740ffeb67123f01dd00"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/662ade4de9ff5eceb0820a9f8e9fac70ba6a815b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/83610ee5e498fa5bfcb80031d2b959baea276bf6"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ae805d204cf1f15b87d1bf3529b4c649f3519420"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98253.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98253"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "RDMA/ucma: Serialize join and leave on copy_to_user failure"
}