CVE-2026-98323
Received
Received - Intake
RDMA/siw Header Copy Length Validation Flaw
Vulnerability report for CVE-2026-98323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Bound fragmented header copies by the remaining length
siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the
next copy length.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | e3917c85f41ef1df64e27dc0e46ab0d803c5e73e |
| Linux | Linux | 308cd50f174c95a507527037f4de1a0396aa4325 |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | 754209850df8367c954ac1de7671c7430b1f342c |
| Linux | Linux | e09caa38e10bcf027100cc22b0e3cc745a39ef0a |
| Linux | Linux | 0c14f795a9eab9344230f9933798b8ee496f497d |
| Linux | Linux | 7fada7c6962219b6fc4ff4e62e46a936af110dd9 |
| Linux | Linux | 5.10.150 |
| Linux | Linux | 5.15.75 |
| Linux | Linux | 5.4.220 |
| Linux | Linux | 5.19.17 |
| Linux | Linux | 6.0.3 |
| Linux | Linux | 6.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |