Boundary Write Vulnerability in Linux Kernel RDMA Implementation
CVE-2026-98323

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98323?

A vulnerability exists in the Linux kernel's Remote Direct Memory Access (RDMA) subsystem, specifically within the siw_get_hdr() function. This issue occurs when an extended DDP/RDMAP header is segmented across more than one TCP callback. As a result, the initial callback may receive a majority of the header, but the subsequent callback miscalculates the remaining bytes to be copied. This can lead to the destination buffer being accessed beyond its intended bounds, potentially overwriting critical state information, including the receive state value. This vulnerability necessitates careful handling of header length calculations to mitigate the risk of out-of-bounds writes.

Affected Version(s)

Linux e3917c85f41ef1df64e27dc0e46ab0d803c5e73e < 2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7

Linux 308cd50f174c95a507527037f4de1a0396aa4325

Linux 754209850df8367c954ac1de7671c7430b1f342c < 262dcd809723723ed8a4e05437ec7e9c21a8f17e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.