CVE-2026-98323: RDMA/siw: Bound fragmented header copies by the remaining length
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Bound fragmented header copies by the remaining length
siwgethdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MINDDPHDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdupartrcvd. A later callback can then use a negative fpdupartrcvd value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the next copy length.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the out-of-bounds write?
The affected SIW receive path must process an extended DDP/RDMAP header fragmented across more than one TCP callback. The first callback must leave part of the header outstanding, and a subsequent callback can over-copy data, corrupt receive state, and later use a negative receive count as a copy offset.
Which systems are exposed?
Systems using the Linux kernel SIW RDMA implementation are relevant to this issue. The provided information does not identify affected kernel versions, default enablement, or specific deployment configurations.
How can I determine whether a system has the fix?
Check whether the installed kernel includes one of the referenced stable commits: 2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7, af9f5b474a260ad23ffb9793d716a5e3bbce3b48, or 262dcd809723723ed8a4e05437ec7e9c21a8f17e9c21a8f17e.