Linux Kernel: 25 Networking and RDMA Vulnerabilities Patched in Single Disclosure Event
25 Linux kernel vulnerabilities impacting networking and RDMA subsystems were disclosed and patched on October 6, 2026.

Key findings
- 25 Linux kernel vulnerabilities disclosed on October 6, 2026, impacting networking and RDMA subsystems.
- Multiple vulnerabilities related to packet handling, buffer management, and state synchronization across various network components.
- Significant number of issues found in RDMA/InfiniBand drivers (rxe, iser, isert) related to memory access and connection management.
- Firmware interaction and clock management vulnerabilities also addressed in ARM SCPI and CLK drivers.
- All disclosed vulnerabilities were patched on the same day, emphasizing a coordinated security response.
On October 6, 2026, a batch of 25 vulnerabilities was disclosed in the Linux kernel, primarily affecting its networking and RDMA subsystems. These vulnerabilities, all patched on the same day, range in severity and could lead to various issues including denial-of-service, information disclosure, and potential privilege escalation.
The vulnerabilities can be broadly categorized by the affected subsystem:
Networking (xfrm, esp, wifi)
Several issues were found within the xfrm (transform) subsystem, which handles IPsec and other security protocols.
CVE-2026-98372andCVE-2026-98371address stack out-of-bounds reads and potential panics during packet reassembly, respectively.CVE-2026-98370fixes a use-after-free vulnerability in the handling of ALLOCSPI requests.CVE-2026-98369resolves missing RCU read locks and device reference counts in packet retransmission, preventing potential race conditions.CVE-2026-98368in theespmodule corrects the downgrade of zerocopy managed fragments before mutation, preventing potential data corruption.
The wifi subsystem also saw multiple fixes:
CVE-2026-98351addresses a bug where skbs were not freed when the simulated link disconnected invirt_wifi.CVE-2026-98350ensures the PMKID is passed to firmware if present inbrcmfmac, preventing potential data leaks.CVE-2026-98349andCVE-2026-98348reject malformed beacon, probe response, and association response frames inlibipw, preventing parsing issues.
RDMA and IB (InfiniBand)
A significant portion of the disclosed vulnerabilities reside in the Remote Direct Memory Access (RDMA) and InfiniBand (IB) components.
CVE-2026-98367,CVE-2026-98366,CVE-2026-98365,CVE-2026-98361,CVE-2026-98360,CVE-2026-98353, andCVE-2026-98352all relate to therxe(RDMA emulation) driver, fixing issues such as incorrect state handling, integer overflows leading to out-of-bounds access, improper access flag checks, multicast group management, and connection interruption handling that could lead to resource leaks.CVE-2026-98358inIB/iserprevents the rejection of remote invalidations for unregistered memory regions.CVE-2026-98357inIB/isertensures that deferred control PDUs are completed before releasing connections.CVE-2026-98356inRDMA/bnxt_readds a check for workqueue creation failure.CVE-2026-98355inRDMA/rtrsguards against null object names during client cleanup.CVE-2026-98354inRDMA/madfixes a receive buffer leak when PKey enforcement fails.CVE-2026-98359inRDMA/corerejects unregistering network devices during speed checks.
Firmware and Clock Management
Two vulnerabilities touch upon firmware interaction and clock management:
CVE-2026-98363infirmware/arm_scpirejects excessive DVFS OPP counts from the SCP firmware.CVE-2026-98362inclk/scpibounds-checks DVFS indices to prevent out-of-bounds access due to potentially buggy firmware.
All these issues were addressed through code patches released on October 6, 2026. Users are advised to update their Linux kernel to a patched version to mitigate these vulnerabilities. The broad range of affected subsystems highlights the complexity and interconnectedness of the Linux kernel's networking stack.
Key findings from this batch include:
- A significant number of vulnerabilities (10+) were found in the RDMA and InfiniBand subsystems, indicating potential areas for focused security review.
- Multiple vulnerabilities across different subsystems (xfrm, RDMA, wifi) were related to improper handling of network packet fragments, buffer management, and state synchronization.
- Several issues stemmed from trusting or improperly validating data received from firmware or network peers, leading to memory corruption or denial-of-service conditions.
- The timely disclosure and patching of these 25 CVEs on a single day suggest a coordinated effort by the Linux kernel security team.
This coordinated disclosure event underscores the importance of regular kernel updates to maintain system security and stability. Users should consult their distribution's security advisories for specific guidance on applying these patches. ,cve_ids:[CVE-2026-98372,CVE-2026-98371,CVE-2026-98370,CVE-2026-98369,CVE-2026-98368,CVE-2026-98367,CVE-2026-98366,CVE-2026-98365,CVE-2026-98364,CVE-2026-98363,CVE-2026-98362,CVE-2026-98361,CVE-2026-98360,CVE-2026-98359,CVE-2026-98358,CVE-2026-98357,CVE-2026-98356,CVE-2026-98355,CVE-2026-98354,CVE-2026-98353,CVE-2026-98352,CVE-2026-98351,CVE-2026-98350,CVE-2026-98349,CVE-2026-98348],image_prompt: