Bug 2546392 (CVE-2026-98323) - CVE-2026-98323 kernel: RDMA/siw: Bound fragmented header copies by the remaining length
Summary: CVE-2026-98323 kernel: RDMA/siw: Bound fragmented header copies by the remain...
Keywords:
Status: NEW
Alias: CVE-2026-98323
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 09:13 UTC by OSIDB Bzimport
Modified: 2026-10-10 07:08 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 09:13:00 UTC
In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Bound fragmented header copies by the remaining length

siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.

Use the number of header bytes already received when calculating the
next copy length.


Note You need to log in before you can comment on or make changes to this bug.