Sceawere

Vulnerability Detail

CVE-2026-98323UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RDMA/siw Out-of-Bounds Write Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-06T09:18:24.403Z",
  "pubdate": "2026-10-06T09:18:24.403Z",
  "executiveSummary": "The Linux kernel's Soft-iWARP (siw) driver contains an out-of-bounds (OOB) write vulnerability located within the header processing logic of the siw_get_hdr() function.\nThis vulnerability is triggered during the reassembly of fragmented DDP (Direct Data Placement) or RDMAP (Remote Direct Memory Access Protocol) headers received across multiple TCP segments.\nImproper length calculations during header copies result in the corruption of internal receive state metadata, specifically the fpdu_part_rcvd variable.\nAn unauthenticated, remote attacker can exploit this flaw by sending specifically crafted fragmented packets to trigger an OOB write, potentially leading to arbitrary memory corruption, system instability, or local privilege escalation.\nThe vulnerability resides in the way the driver manages header copy boundaries when fragments are processed non-atomically. Successful exploitation requires the ability to reach the siw network interface and perform multiple TCP-based fragment injections.\nThe primary risk implication is a compromise of the kernel memory space managed by the siw driver, impacting the integrity and availability of the affected Linux kernel instance.",
  "technicalDetails": "The root cause of the vulnerability lies in the logic governing fragmented header copies within the siw_get_hdr() function of the Linux kernel's siw driver. The function is designed to reconstruct extended DDP/RDMAP headers that span multiple TCP callbacks. However, the calculation of the destination buffer limit for subsequent fragments is flawed.\nIn the vulnerable implementation, the code restricts the copy length based on a static header length subtraction (hdrlen - MIN_DDP_HDR) rather than the actual remaining byte count required to complete the header. When a partial header is received, the subsequent callback incorrectly calculates the offset, causing the destination pointer to advance past the expected memory buffer. This overflow overwrites adjacent data structures, including the critical fpdu_part_rcvd field, which tracks the number of received bytes in the current PDU.\nExploitation proceeds via the following attack flow: 1. The attacker initiates a connection using the iWARP protocol. 2. The attacker injects a specially crafted TCP stream containing fragmented RDMAP/DDP headers. 3. The first fragment is processed normally, but the subsequent fragment triggers the flawed boundary check in siw_get_hdr(). 4. The driver overwrites the memory offset used for tracking the PDU fragment, setting fpdu_part_rcvd to an attacker-controlled or negative value. 5. In a subsequent callback, the driver uses this corrupted negative value as an offset index for a memory copy operation. 6. The resulting OOB write allows the attacker to corrupt kernel memory regions adjacent to the receive state structures.\nThe vulnerability specifically affects the siw driver's memory management logic for fragmented headers. Because the corruption occurs within the context of the kernel stack or kernel heap used by the networking subsystem, the impact is critical. Authentication is not required, as the vulnerability is reachable through the network interface via standard RDMA-over-TCP interactions. The exploitation process is deterministic, relying on the predictable behavior of the siw state machine when presented with fragmented, out-of-sequence header data."
}
CVE-2026-98323: RDMA/siw Out-of-Bounds Write Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere