PT-2026-106694 · Linux · Linux

CVE-2026-98365

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix integer overflow in mr check range() leading to OOB access
mr check range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic:
if (iova < mr->ibmr.iova || iova + length > mr->ibmr.iova + mr->ibmr.length)
A remote peer can craft an RDMA-Write/Read RETH so that iova + length wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the check. rxe mr iova to index() then computes a huge index (int idx, only guarded by WARN ON) and rxe mr copy xarray() dereferences mr->page info[huge], causing an out-of-bounds read/write and a kernel oops that is triggerable by an unauthenticated remote peer.
Rewrite the check in overflow-safe form; the first two clauses guarantee that the subsequent subtractions do not underflow:
if (iova < mr->ibmr.iova || length > mr->ibmr.length || iova - mr->ibmr.iova > mr->ibmr.length - length)
With the fix, mr check range() returns -EINVAL for the crafted iova and the responder reports REMOTE ACCESS ERROR instead of triggering the OOB.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98365

Affected Products

Linux