Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Bound fragmented header copies by the remaining length

siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.

Use the number of header bytes already received when calculating the
next copy length.
Published: 2026-10-06
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds write that can lead to arbitrary memory corruption or code execution
Action: Apply patch
AI Analysis

Impact

siw_get_hdr() can receive an extended DDP/RDMAP header that is delivered over multiple TCP callbacks. During a subsequent callback the copy length is calculated incorrectly as hdrlen – MIN_DDP_HDR instead of the number of bytes still missing, causing the buffer pointer to advance past the end of the header. This overwrites the receive state, including the fpdu_part_rcvd field. A later callback then interprets the negative fpdu_part_rcvd value as a copy offset, producing an out‑of‑bounds write.

Affected Systems

The flaw exists in the Linux kernel in all builds that support RDMA silicon interconnect (siw) functionality. No specific kernel version range is listed, so any system using Kernel with siw enabled is potentially affected.

Risk and Exploitability

The vulnerability is an out‑of‑bounds write, which is a high‑impact defect. No CVSS, EPSS, or KEV data is currently available; the issue is not listed in the CISA KEV catalogue. It is inferred that the attack vector requires an attacker to transmit crafted RDMA traffic to the target system, a scenario that is likely to be observed only in environments that expose RDMA services to an untrusted network. Because the code path influences kernel state, successful exploitation could lead to kernel memory corruption, privilege escalation, or denial of service.

Generated by OpenCVE AI on October 6, 2026 at 12:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a revision that incorporates the siw header copy fix referenced in the kernel commit logs
  • Restart to load the updated kernel image and ensure the patched code is active
  • If the patch is unavailable or cannot be applied, disable RDMA/siw functionality by unloading the related module or setting the appropriate sysctl to prevent RDMA traffic from being processed

Generated by OpenCVE AI on October 6, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.
Title RDMA/siw: Bound fragmented header copies by the remaining length
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:46:17.150Z

Reserved: 2026-09-25T10:25:14.340Z

Link: CVE-2026-98323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:24.403

Modified: 2026-10-06T09:18:24.403

Link: CVE-2026-98323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T13:00:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write