PT-2026-98047 · Linux · Linux Kernel

CVE-2026-97413

·

Published

2026-09-24

·

Updated

2026-09-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An unauthenticated RDMA client can trigger an integer underflow in the RTRS (RDMA Transparent RPC Service) component. The issue occurs in the process read() and process write() functions, where the usr len variable is read from a network-supplied message field and used to calculate data len by subtracting usr len from off. Because the system fails to validate that usr len is less than or equal to off, a malicious client can provide a usr len value greater than off. This causes the data len to wrap to a very large size t value, which is then passed to the rdma ev callback as a memory length, resulting in out-of-bounds kernel memory access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97413

Affected Products

Linux Kernel