Impact
siw_get_hdr() can receive an extended DDP/RDMAP header that is delivered over multiple TCP callbacks. During a subsequent callback the copy length is calculated incorrectly as hdrlen – MIN_DDP_HDR instead of the number of bytes still missing, causing the buffer pointer to advance past the end of the header. This overwrites the receive state, including the fpdu_part_rcvd field. A later callback then interprets the negative fpdu_part_rcvd value as a copy offset, producing an out‑of‑bounds write.
Affected Systems
The flaw exists in the Linux kernel in all builds that support RDMA silicon interconnect (siw) functionality. No specific kernel version range is listed, so any system using Kernel with siw enabled is potentially affected.
Risk and Exploitability
The vulnerability is an out‑of‑bounds write, which is a high‑impact defect. No CVSS, EPSS, or KEV data is currently available; the issue is not listed in the CISA KEV catalogue. It is inferred that the attack vector requires an attacker to transmit crafted RDMA traffic to the target system, a scenario that is likely to be observed only in environments that expose RDMA services to an untrusted network. Because the code path influences kernel state, successful exploitation could lead to kernel memory corruption, privilege escalation, or denial of service.
OpenCVE Enrichment