Microsoft Security Response Center guidance
Vendor revision: Oct 7, 2026Release Notes
Vulnerability intelligence
CVE-2026-98252 and is rated High severity with a CVSS score of 7.0. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail() making it accessible to global list where another CPU can kref_get() on nlmsg_request causing a refcount "addition on 0" bug. Fix this by initializing kref _before_ list_add_tail() so refcount for nlmsg_request can be incremented/decremented normally. In addition, also initialize every field before list_add_tail().
Source: NVD