Answer in brief
CVE-2026-98352 records a Unknown severity vulnerability in RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <a82cca40139d9fcae8208901856bd5bb4051f097 || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <74c4ed55e61f1b65ddbebc5b635d136461a1c3da || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <6f8020fe7465f49e234a576c04e415e9d08c7878 || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <31024e158b45358370a0a14ed96589e6aa62d6cb || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <8f253d5893f991742464b9e7203c43fc08d0aa11 || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <bf88ac4867050112a6c819c8d1a7209bf48ef427 || >=3b89e92c2a95a39c38a3808f4528e502a39bd94d <2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda | a82cca40139d9fcae8208901856bd5bb4051f097, 74c4ed55e61f1b65ddbebc5b635d136461a1c3da, 6f8020fe7465f49e234a576c04e415e9d08c7878, 31024e158b45358370a0a14ed96589e6aa62d6cb, 8f253d5893f991742464b9e7203c43fc08d0aa11, bf88ac4867050112a6c819c8d1a7209bf48ef427, 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted The client borrows shared CQ credits in the ADDR_RESOLVED handler via ib_cq_pool_get(), before the peer is connected. create_cm() can return -ERESTARTSYS from wait_event_interruptible_timeout() without destroying the CM ID. The init_conns() and stop-and-destroy paths then call destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards rdma_destroy_id(). CMA serializes the handler against rdma_destroy_id() with handler_mutex, but that does not order the GET against destroy_con_cq_qp(). If ADDR_RESOLVED has already passed the DESTROYING check, it can take con_mutex, GET credits, and then lose the con to kfree. Device unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup(). Set a per-connection flag under con_mutex before CQ/QP teardown so a racing ADDR_RESOLVED cannot borrow credits after teardown has begun.
Quoted source text, attributed separately from HOL analysis.