PT-2026-106652 · Linux · Linux

CVE-2026-98323

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Bound fragmented header copies by the remaining length
siw get hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN DDP HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu part rcvd. A later callback can then use a negative fpdu part rcvd value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the next copy length.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98323

Produtos afetados

Linux