Integer Overflow Vulnerability in Linux Kernel Affecting RDMA Functionality
CVE-2026-98365

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98365?

A recent vulnerability in the Linux kernel's RDMA functionality allowed exploitative manipulation of the mr_check_range() function due to an integer overflow. This flaw came from improper validation of the memory range access, allowing a remote peer to craft requests that could lead to out-of-bounds (OOB) access. Specifically, the vulnerability could be triggered when the combination of the input address (iova) and a crafted length caused arithmetic wraparound, exceeding the intended memory management boundaries. The consequence was a potential kernel crash or unauthorized access, which has been addressed in the latest version by rewriting the validation checks to prevent such overflow scenarios, ensuring safer memory range verification.

Affected Version(s)

Linux 8700e3e7c4857d28ebaa824509934556da0b3e76

Linux 8700e3e7c4857d28ebaa824509934556da0b3e76 < 5d9426a74fc8cb8f375fcdc19b465a030f9b8cab

Linux 8700e3e7c4857d28ebaa824509934556da0b3e76 < 2f3b705144e3a3c14184fec6e354680081fe91ec

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.