VYPR
Vypr IntelligenceAI-generatedOct 6, 2026· 25 CVEs

Linux Kernel: 25 Networking and RDMA Vulnerabilities Patched in Single Disclosure Event

25 Linux kernel vulnerabilities impacting networking and RDMA subsystems were disclosed and patched on October 6, 2026.

Key findings

  • 25 Linux kernel vulnerabilities disclosed on October 6, 2026, impacting networking and RDMA subsystems.
  • Multiple vulnerabilities related to packet handling, buffer management, and state synchronization across various network components.
  • Significant number of issues found in RDMA/InfiniBand drivers (rxe, iser, isert) related to memory access and connection management.
  • Firmware interaction and clock management vulnerabilities also addressed in ARM SCPI and CLK drivers.
  • All disclosed vulnerabilities were patched on the same day, emphasizing a coordinated security response.

On October 6, 2026, a batch of 25 vulnerabilities was disclosed in the Linux kernel, primarily affecting its networking and RDMA subsystems. These vulnerabilities, all patched on the same day, range in severity and could lead to various issues including denial-of-service, information disclosure, and potential privilege escalation.

The vulnerabilities can be broadly categorized by the affected subsystem:

Networking (xfrm, esp, wifi)

Several issues were found within the xfrm (transform) subsystem, which handles IPsec and other security protocols.

  • CVE-2026-98372 and CVE-2026-98371 address stack out-of-bounds reads and potential panics during packet reassembly, respectively.
  • CVE-2026-98370 fixes a use-after-free vulnerability in the handling of ALLOCSPI requests.
  • CVE-2026-98369 resolves missing RCU read locks and device reference counts in packet retransmission, preventing potential race conditions.
  • CVE-2026-98368 in the esp module corrects the downgrade of zerocopy managed fragments before mutation, preventing potential data corruption.

The wifi subsystem also saw multiple fixes:

  • CVE-2026-98351 addresses a bug where skbs were not freed when the simulated link disconnected in virt_wifi.
  • CVE-2026-98350 ensures the PMKID is passed to firmware if present in brcmfmac, preventing potential data leaks.
  • CVE-2026-98349 and CVE-2026-98348 reject malformed beacon, probe response, and association response frames in libipw, preventing parsing issues.

RDMA and IB (InfiniBand)

A significant portion of the disclosed vulnerabilities reside in the Remote Direct Memory Access (RDMA) and InfiniBand (IB) components.

  • CVE-2026-98367, CVE-2026-98366, CVE-2026-98365, CVE-2026-98361, CVE-2026-98360, CVE-2026-98353, and CVE-2026-98352 all relate to the rxe (RDMA emulation) driver, fixing issues such as incorrect state handling, integer overflows leading to out-of-bounds access, improper access flag checks, multicast group management, and connection interruption handling that could lead to resource leaks.
  • CVE-2026-98358 in IB/iser prevents the rejection of remote invalidations for unregistered memory regions.
  • CVE-2026-98357 in IB/isert ensures that deferred control PDUs are completed before releasing connections.
  • CVE-2026-98356 in RDMA/bnxt_re adds a check for workqueue creation failure.
  • CVE-2026-98355 in RDMA/rtrs guards against null object names during client cleanup.
  • CVE-2026-98354 in RDMA/mad fixes a receive buffer leak when PKey enforcement fails.
  • CVE-2026-98359 in RDMA/core rejects unregistering network devices during speed checks.

Firmware and Clock Management

Two vulnerabilities touch upon firmware interaction and clock management:

  • CVE-2026-98363 in firmware/arm_scpi rejects excessive DVFS OPP counts from the SCP firmware.
  • CVE-2026-98362 in clk/scpi bounds-checks DVFS indices to prevent out-of-bounds access due to potentially buggy firmware.

All these issues were addressed through code patches released on October 6, 2026. Users are advised to update their Linux kernel to a patched version to mitigate these vulnerabilities. The broad range of affected subsystems highlights the complexity and interconnectedness of the Linux kernel's networking stack.

Key findings from this batch include:

  • A significant number of vulnerabilities (10+) were found in the RDMA and InfiniBand subsystems, indicating potential areas for focused security review.
  • Multiple vulnerabilities across different subsystems (xfrm, RDMA, wifi) were related to improper handling of network packet fragments, buffer management, and state synchronization.
  • Several issues stemmed from trusting or improperly validating data received from firmware or network peers, leading to memory corruption or denial-of-service conditions.
  • The timely disclosure and patching of these 25 CVEs on a single day suggest a coordinated effort by the Linux kernel security team.

This coordinated disclosure event underscores the importance of regular kernel updates to maintain system security and stability. Users should consult their distribution's security advisories for specific guidance on applying these patches. ,cve_ids:[CVE-2026-98372,CVE-2026-98371,CVE-2026-98370,CVE-2026-98369,CVE-2026-98368,CVE-2026-98367,CVE-2026-98366,CVE-2026-98365,CVE-2026-98364,CVE-2026-98363,CVE-2026-98362,CVE-2026-98361,CVE-2026-98360,CVE-2026-98359,CVE-2026-98358,CVE-2026-98357,CVE-2026-98356,CVE-2026-98355,CVE-2026-98354,CVE-2026-98353,CVE-2026-98352,CVE-2026-98351,CVE-2026-98350,CVE-2026-98349,CVE-2026-98348],image_prompt:

AI-written article. Grounded in 25 CVE records listed below.