PT-2026-98047 · Linux · Linux Kernel
CVE-2026-97413
·
Published
2026-09-24
·
Updated
2026-09-26
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An unauthenticated RDMA client can trigger an integer underflow in the RTRS (RDMA Transparent RPC Service) component. The issue occurs in the
process read() and process write() functions, where the usr len variable is read from a network-supplied message field and used to calculate data len by subtracting usr len from off. Because the system fails to validate that usr len is less than or equal to off, a malicious client can provide a usr len value greater than off. This causes the data len to wrap to a very large size t value, which is then passed to the rdma ev callback as a memory length, resulting in out-of-bounds kernel memory access.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel