{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: validate access flags before swapping the MR's PD  rxe_rereg_user_mr() reassigns mr-\u003eibmr.pd first and only then validates the IB_MR_REREG_ACCESS argument:  \tif (flags \u0026 IB_MR_REREG_PD) { \t\trxe_put(old_pd); \t\trxe_get(pd); \t\tmr-\u003eibmr.pd = ibpd; \t}  \tif (flags \u0026 IB_MR_REREG_ACCESS) { \t\tif (access \u0026 ~RXE_ACCESS_SUPPORTED_MR) \t\t\treturn ERR_PTR(-EOPNOTSUPP); \t\tmr-\u003eaccess = access; \t}  Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access check with mr-\u003eibmr.pd already reassigned.  mr-\u003eibmr.pd is owned by the core, which adjusts pd-\u003eusecnt only on the success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error without undoing the reassignment, so mr-\u003epd == new_pd while the usecnts still charge the MR to orig_pd. ib_dereg_mr_user() then decrements new_pd, whose count can reach zero while a memory window still references it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup() writes to freed memory:    BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0   Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591    __rxe_put+0x31/0xa0    rxe_mw_cleanup+0x42/0x200    __rxe_cleanup+0x115/0x370    rxe_dealloc_mw+0x4c/0x80   Allocated by task 591:    ib_uverbs_alloc_pd+0x258/0x540   Freed by task 591:    ib_dealloc_pd_user+0x174/0x210    uverbs_free_pd+0x8d/0xc0    ib_uverbs_dealloc_pd+0x18e/0x1d0  Validate the access flags before mutating any state so the callback either applies every requested change or none.",
  "id": "DEBIAN-CVE-2026-98366",
  "modified": "2026-10-08T09:47:38.861129711Z",
  "published": "2026-10-06T09:18:30.823Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98366"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-98366"
  ]
}