Sceawere
Vulnerability Detail
CVE-2026-98365UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Kernel RDMA Integer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: if (iova < mr->ibmr.iova || iova + length > mr->ibmr.iova + mr->ibmr.length) A remote peer can craft an RDMA-Write/Read RETH so that iova + length wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the check. rxe_mr_iova_to_index() then computes a huge index (int idx, only guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences mr->page_info[huge], causing an out-of-bounds read/write and a kernel oops that is triggerable by an unauthenticated remote peer. Rewrite the check in overflow-safe form; the first two clauses guarantee that the subsequent subtractions do not underflow: if (iova < mr->ibmr.iova || length > mr->ibmr.length || iova - mr->ibmr.iova > mr->ibmr.length - length) With the fix, mr_check_range() returns -EINVAL for the crafted iova and the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-06T09:18:30.677Z",
"pubdate": "2026-10-06T09:18:30.677Z",
"executiveSummary": "The vulnerability in the Linux kernel's RDMA/rxe (Soft RoCE) implementation involves an integer overflow in the mr_check_range() function. This flaw allows a remote, unauthenticated attacker to bypass Memory Region (MR) boundary validation through crafted RDMA-Write or RDMA-Read requests.\nBy manipulating the 'iova' and 'length' parameters to induce an integer wraparound, the attacker can cause the validation logic to incorrectly permit access to memory outside of the registered MR.\nThe primary impact of this vulnerability is an out-of-bounds (OOB) memory read or write, leading to a kernel oops (panic), potential information disclosure, or memory corruption. The vulnerability is highly severe as it is triggerable over the network by an unauthenticated remote peer without requiring prior privileges.\nThis vulnerability highlights a critical failure in input validation arithmetic, where reliance on unsafe addition operations enables attackers to circumvent security boundaries. Immediate application of the kernel patch is required to enforce safe range checking.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of bounds checking within the mr_check_range() function in the RDMA/rxe component. The original validation logic utilized the expression 'iova + length > mr->ibmr.iova + mr->ibmr.length' to verify that an RDMA operation's range [iova, iova+length) resides within the bounds of a registered Memory Region.\nBecause the check uses standard addition, an attacker can craft a malicious RETH (Remote Entry Target Header) containing an 'iova' and 'length' combination that results in an integer wraparound (overflow) of the sum, effectively resetting the value to a very small number or zero. For instance, providing an 'iova' of 0xfffffffffffffff8 and a 'length' of 8 causes the addition to wrap, bypassing the bounds check.\nOnce the check is bypassed, the execution flow proceeds to rxe_mr_iova_to_index(). This function relies on the corrupted or unvalidated input to calculate an index into the mr->page_info structure. Due to the overflow, a massive, out-of-range index is generated. Subsequently, rxe_mr_copy_xarray() attempts to perform a read or write operation using this invalid index.\nThe attack flow proceeds as follows: 1) An unauthenticated attacker initiates an RDMA connection to the vulnerable host. 2) The attacker sends a crafted RDMA-Write or RDMA-Read packet with specific parameters designed to trigger the integer overflow during range verification. 3) The kernel’s mr_check_range() fails to identify the illegal memory access due to the wraparound. 4) The kernel performs a memory operation at an arbitrary, OOB memory location, resulting in a kernel oops, memory corruption, or system crash.\nThe fix replaces the problematic overflow-prone arithmetic with a safer validation strategy. By verifying that 'iova < mr->ibmr.iova', 'length > mr->ibmr.length', and finally 'iova - mr->ibmr.iova > mr->ibmr.length - length', the kernel ensures that subtractions will not underflow. This logic forces the function to correctly identify out-of-bounds requests and return -EINVAL, causing the RDMA responder to return a REMOTE_ACCESS_ERROR rather than executing the dangerous memory operation."
}