Bug 2546432 (CVE-2026-98352) - CVE-2026-98352 kernel: RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
Summary: CVE-2026-98352 kernel: RDMA/rtrs-clt: Fix CQ pool leak when connect is interr...
Keywords:
Status: NEW
Alias: CVE-2026-98352
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:20 UTC by OSIDB Bzimport
Modified: 2026-10-10 14:53 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:20:02 UTC
In the Linux kernel, the following vulnerability has been resolved:

RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted

The client borrows shared CQ credits in the ADDR_RESOLVED handler via
ib_cq_pool_get(), before the peer is connected. create_cm() can return
-ERESTARTSYS from wait_event_interruptible_timeout() without destroying
the CM ID. The init_conns() and stop-and-destroy paths then call
destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards
rdma_destroy_id().

CMA serializes the handler against rdma_destroy_id() with handler_mutex,
but that does not order the GET against destroy_con_cq_qp(). If
ADDR_RESOLVED has already passed the DESTROYING check, it can take
con_mutex, GET credits, and then lose the con to kfree. Device
unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().

Set a per-connection flag under con_mutex before CQ/QP teardown so a
racing ADDR_RESOLVED cannot borrow credits after teardown has begun.


Note You need to log in before you can comment on or make changes to this bug.