CVE-2026-98252 PUBLISHED

RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()

iwpm_get_nlmsg_request() initializes refcount after list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref before list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 52c13c63bb3662c108244e7447055e30bf40244e (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 8a91609032d47e77bcb37bc8f6e88d89340d2709 (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to ce8a379598bd4058081416abea4279fd05a95374 (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 2fbac8a56004b6ce54fbfe845d4b25da6e0b55e8 (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 88e429a4e9bac3d2138011c5ca06254331f2587f (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to e15eb536be4f646ce683d2867572b2200be877f7 (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 117871cdb8927542abd7b65ce5995bf0265a8c05 (excl.)
  • affected from 30dc5e63d6a5ad24894b5512d10b228d73645a44 to 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.16 is affected
  • unaffected from 0 to 3.16 (excl.)
  • unaffected from 5.10.271 to 5.10.* (incl.)
  • unaffected from 5.15.222 to 5.15.* (incl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References