Impact
An integer underflow in the svc_rdma_read_chunk_range function of the Linux kernel causes incorrect DMA length calculations during RDMA read operations. When a segment offset equals the segment length, the skip predicate fails to skip the fully consumed segment, resulting in a subtraction that underflows a 32‑bit value to near U32_MAX. This underflow propagates into a huge number of page vector descriptors fed to svc_rdma_build_read_segment, leading the kernel to allocate an excessively large kmalloc array and corrupt memory. The failure can trigger a kernel panic or malicious data modification, as the corrupted memory is used by further RDMA processing.
Affected Systems
All Linux distributions running a kernel that includes the svc_rdma (RDMA) subsystem prior to the commit that introduces the fix are affected. The vulnerability is present in any kernel prior to the patch, regardless of vendor or distribution; thus clients of RDMA services on any affected host are at risk.
Risk and Exploitability
The CVSS base score of 9.8 classifies the flaw as critical, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. A likely attack vector is an RDMA client able to send malformed read requests to the vulnerable host, potentially triggering malformed DMA operations that corrupt kernel memory and cause a denial of service. An attacker would need the ability to initiate RDMA traffic to the target; local or remote exploitation is possible depending on RDMA exposure configuration.
OpenCVE Enrichment
Debian DSA