← All Advisories

Linux Kernel RDMA/rxe On-Demand Paging Omits HMM_PFN_WRITE Flag, Allowing a Local User to Overwrite Read-Only File Mappings

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98361

Key Details

CVECVE-2026-98361
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths

Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO

pages") dropped the access permission test from rxe_check_pagefault()

and left only HMM_PFN_VALID. A page faulted in read-only, for example

a page-cache folio behind a PROT_READ file mapping, then satisfies the

check and ODP write operations (RDMA WRITE, RDMA READ response, SEND

payload, atomics) modify it through kmap without ever breaking CoW.

An unprivileged user can register an ODP MR over such a mapping and

have incoming RDMA traffic overwrite the page cache of a file it only

holds O_RDONLY, including /etc/passwd or setuid binaries. This is the

same primitive class as Dirty COW and CVE-2022-2590.

mlx5 has the missing invariant: its ODP path sets the device write bit

only for pfns that carry HMM_PFN_WRITE. Restore it in rxe by requiring

HMM_PFN_WRITE in rxe_check_pagefault() for every operation except

RXE_PAGEFAULT_RDONLY. A write to a non-writable VMA now fails the one

fault attempt with -EPERM from hmm_vma_fault() instead of re-faulting

forever. For a writable VMA the fault breaks CoW and the write lands

in the private page.

Keep pmem flushes on the read-only check. arch_wb_cache_pmem() never

modifies memory, and the FLUSH access bits do not make the umem

writable, so classifying flushes as writes would make every flush

against a flush-only MR fail. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98361
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98361