PT-2026-106652 · Linux · Linux

CVE-2026-98323

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Bound fragmented header copies by the remaining length
siw get hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN DDP HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu part rcvd. A later callback can then use a negative fpdu part rcvd value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the next copy length.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98323

Affected Products

Linux