{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97413","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.867Z","datePublished":"2026-09-24T16:03:21.010Z","dateUpdated":"2026-10-03T10:58:05.684Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:05.684Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Fix integer underflow in process_read and process_write\n\nusr_len is read from a network-supplied message field (le16_to_cpu)\nand used to compute data_len = off - usr_len without validating that\nusr_len <= off. A malicious RDMA client can send usr_len > off causing\nan integer underflow, resulting in data_len wrapping to a huge size_t\nvalue which is then passed to the rdma_ev callback as a memory length,\nleading to out-of-bounds memory access.\n\nFix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids()\nin both process_read() and process_write(), ensuring the early return\npath acquires no reference and has no resource leak."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - A remote peer RDMA-WRITE-WITH-IMM's a RTRS_MSG_READ or RTRS_MSG_WRITE carrying attacker-controlled usr_len; rtrs_srv_rdma_done() hands that buffer to process_io_req() then process_read()/process_write(). rtrs_srv_cm_init() listens with RDMA_PS_TCP on IPv6 port 1234 (RoCEv2/iWARP), which is IP-routable.\nAC:L - The peer sets le16 usr_len in the RTRS_MSG_READ/WRITE at chunk+off and the IMM payload that rtrs_srv_rdma_done() splits into msg_id and off. Choosing usr_len > off makes size_t data_len = off - usr_len wrap on every call; there is no race and no victim-held state.\nPR:N - rtrs_rdma_connect() admits the RDMA_CM CONNECT_REQUEST after checking only RTRS_MAGIC, protocol major version, and cid/uuid; process_info_req() then publishes chunk rkeys and moves to RTRS_SRV_CONNECTED with no credentials, so process_read()/process_write() run unauthenticated.\nUI:N - The attacker posts the RDMA-WRITE-WITH-IMM that rtrs_srv_rdma_done() delivers to process_read()/process_write(); no local user must mount a volume, open a file, or otherwise interact.\nS:U - process_read()/process_write() invoke rnbd_srv_rdma_ev() in the same host kernel that owns the chunk pages; the OOB access stays inside that kernel and does not escape a VM, guest, or IOMMU domain.\nC:H - Underflowed data_len makes usr = page_address(chunk)+off-usr_len point before the chunk. rnbd_srv_rdma_ev() reads the RNBD header there; a sprayed RNBD_MSG_OPEN does unbounded strlen(dev_name), and process_rdma() bio_add_virt_nofail()s a ~4GiB WRITE bvec that copies following linear-map pages onto a device the peer can read back.\nI:H - process_rdma() truncates the wrapped size_t to u32 and bio_add_virt_nofail() installs a ~4GiB bvec from the chunk page; submit_bio() of an RNBD_OP_READ therefore writes device data through that bvec into subsequent kernel linear-map pages, an out-of-bounds kernel write.\nA:H - rnbd_srv_rdma_ev() immediately loads hdr->type from the wrapped usr pointer, process_msg_open() strlen()s that OOB name, and the ~4GiB bio_add_virt_nofail() bvec walks into holes or MMIO in the linear map; any of those oops/panic the completion path and can be repeated at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/ulp/rtrs/rtrs-srv.c"],"versions":[{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"6b1e26e70d7ca9f0906af2283558a530eeb1f066","status":"affected","versionType":"git"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"2c52b2afded988233cd4ccc185cf5147bbc77a76","status":"affected","versionType":"git"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"b042b4947752df0b3d16e683ac09fb4f7f0e33e0","status":"affected","versionType":"git"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"24ad03bfeda05fca04c56677e57fd3d6bc3e9978","status":"affected","versionType":"git"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"c76e9123ab91a903396d26e6ab1b5caae5c6b149","status":"affected","versionType":"git"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"54bf38b27afc08a0eb6b732f9c14eb8a4bcb66b5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/ulp/rtrs/rtrs-srv.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6b1e26e70d7ca9f0906af2283558a530eeb1f066"},{"url":"https://git.kernel.org/stable/c/2c52b2afded988233cd4ccc185cf5147bbc77a76"},{"url":"https://git.kernel.org/stable/c/b042b4947752df0b3d16e683ac09fb4f7f0e33e0"},{"url":"https://git.kernel.org/stable/c/24ad03bfeda05fca04c56677e57fd3d6bc3e9978"},{"url":"https://git.kernel.org/stable/c/c76e9123ab91a903396d26e6ab1b5caae5c6b149"},{"url":"https://git.kernel.org/stable/c/54bf38b27afc08a0eb6b732f9c14eb8a4bcb66b5"}],"title":"RDMA/rtrs-srv: Fix integer underflow in process_read and process_write","x_generator":{"engine":"bippy-1.2.0"}}}}