Impact
A kernel bug in the RDMA/siw read‑response handling allows a connected peer to send read‑response segments that extend beyond the allocated sink buffer because the cumulative offset is not checked on continuation fragments. The resulting out‑of‑bounds memory write can corrupt kernel memory, potentially leading to privilege escalation, arbitrary code execution, or kernel panic. This flaw corresponds to CWE‑787.
Affected Systems
The vulnerability affects the Linux kernel; no specific version range is listed in the CVE data, so any kernel build that does not incorporate the patch is considered vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low but non‑zero likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. However, the flaw can be triggered by an attacker who can open an RDMA connection as the remote peer, requiring no local privilege. Given the high impact of a kernel memory corruption, the risk remains significant for exposed RDMA services.
OpenCVE Enrichment
Debian DLA