{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "a926a903b7dc39a8a949150258c09290998dd812"
            },
            {
              "fixed": "ddb43ac0926d4a931bc9b7744b93627f627457e5"
            },
            {
              "fixed": "c79a789aa15180a1543b5db49c343d12e3ec214d"
            },
            {
              "fixed": "faae1fb4ccf8205806a8802c008798dabeb0205b"
            },
            {
              "fixed": "02c0a2fa69c16248a7432af8a6d64ab2a73a5283"
            },
            {
              "fixed": "d4fc4e37f8a143b0fe83b42c8fb48cf542154fee"
            },
            {
              "fixed": "1caceeb2d74bbe88223aea55eb8626b4c5f076fd"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.18.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98360.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds\n\nrxe_get_mcg() publishes a newly allocated multicast group in\nrxe-\u003emcg_tree before programming the backing Ethernet multicast address\nwith rxe_mcast_add(), which runs outside mcg_lock. A local userspace\nRDMA client reaches this path with ATTACH_MCAST on a UD QP; if\nrxe_mcast_add() then returns an error (for example -ENODEV when the\nbacking netdev has been removed, or a propagated dev_mc_add() error),\nthe unwind frees the published group without removing it from the tree.\nA later lookup of the same MGID dereferences the freed struct rxe_mcg\nfrom __rxe_lookup_mcg().\n\nFix this by keeping the new mcg private until rxe_mcast_add() succeeds.\nSplit the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()\nbefore taking the tree reference, and free the still-private mcg on\nfailure. Because the group is never visible in mcg_tree until the\nmulticast address is programmed, no concurrent caller can look it up or\nattach a QP to a group that is about to be torn down, so the error path\nneeds no conditional unwind. If another caller publishes the same MGID\nwhile the address is being programmed, the post-add re-check under\nmcg_lock finds the winner; this caller then drops its private object and\nbalances its own rxe_mcast_add() with rxe_mcast_del() before returning\nthe winner.\n\nReproduced by forcing the rxe_mcast_add() error return under KASAN:\nwithout the change the next attach to the same MGID reports a\nslab-use-after-free in __rxe_lookup_mcg(); with it the forced failure\nreturns cleanly. A no-injection attach/detach regression, including a\ntwo-QP shared join/leave and re-attach, stays KASAN- and leak-clean.",
  "id": "CVE-2026-98360",
  "modified": "2026-10-08T02:30:57.473541830Z",
  "published": "2026-10-06T08:46:46.743Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/02c0a2fa69c16248a7432af8a6d64ab2a73a5283"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1caceeb2d74bbe88223aea55eb8626b4c5f076fd"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c79a789aa15180a1543b5db49c343d12e3ec214d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d4fc4e37f8a143b0fe83b42c8fb48cf542154fee"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ddb43ac0926d4a931bc9b7744b93627f627457e5"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/faae1fb4ccf8205806a8802c008798dabeb0205b"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98360.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98360"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds"
}