{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97421","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.868Z","datePublished":"2026-09-24T16:03:31.505Z","dateUpdated":"2026-10-03T10:58:13.282Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:13.282Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz()\n\nSeveral corner cases, especially important on 32 bits:\n\n- umem->iova is u64, the function argument should pass in u64 or\n  iova will be truncated\n- Check that the length is not too large for the iova\n- Check that lengths > 4G don't overflow the GENMASK"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Attacker-controlled cmd.hca_va and cmd.length reach ib_umem_find_best_pgsz() via open of /dev/infiniband/uverbsX, then ib_uverbs_write(IB_USER_VERBS_CMD_REG_MR)/ib_uverbs_reg_mr() or UVERBS_METHOD_REG_MR ioctl, then pd->ops.reg_user_mr() (mlx5_ib_reg_user_mr/irdma_reg_user_mr/efa_register_mr). Remote RDMA packets do not supply virt or umem->length.\nAC:L - ib_uverbs_reg_mr() only requires (start & ~PAGE_MASK)==(hca_va & ~PAGE_MASK), so the attacker picks hca_va near 2^63 or U64_MAX with a small pinned region and makes (umem->length-1+virt) overflow or bits_per() return BITS_PER_LONG, hitting the unguarded GENMASK() deterministically with no race.\nPR:L - uverbs_devnode() creates /dev/infiniband/uverbs* mode 0666 and ib_uverbs_open() has no capability check (only rdma_dev_access_netns). ib_umem_get_va() needs can_do_mlock() (RLIMIT_MEMLOCK!=0) and ib_check_mr_access(); CAP_SYS_ADMIN/CAP_IPC_LOCK are not required.\nUI:N - After opening uverbs the attacker allocates a PD and issues IB_USER_VERBS_CMD_REG_MR or UVERBS_METHOD_REG_MR with their own start, length, and hca_va; no victim mount or other user action is required.\nS:U - A wrong page size or truncated umem->iova from ib_umem_find_best_pgsz() misprograms that host's RDMA MTT/PBL. This stays in the kernel/device memory-management authority and is not a KVM/Xen guest-to-host escape or IOMMU VM-boundary bypass.\nC:H - When bits_per((umem->length-1+virt)^virt)>=BITS_PER_LONG, GENMASK(BITS_PER_LONG-1, bits) is invalid and mask can be 0, so the function returns rounddown_pow_of_two(pgsz_bitmap) (largest HW page). mlx5_ib_populate_pas()/rdma_umem_for_each_dma_block() then install oversized MTT/PBL entries, so the NIC DMA-reads physical memory beyond the pinned umem.\nI:H - The same oversized page size is programmed into hardware (efa_register_mr params.page_shift, ionic_pgtbl_init, mlx5 mkey PAS). With IB_ACCESS_LOCAL_WRITE or IB_ACCESS_REMOTE_WRITE from the REG_MR access_flags, the device DMA-writes outside the registered region, which is an arbitrary physical write.\nA:H - GENMASK() with l>h is a shift UB that can oops (UBSAN) or yield mask==0; mis-sized pages cause IOMMU/device faults. ib_umem_is_contiguous() (mlx5_ib_db_map_user_desc, efa create_cq) can also treat a non-contiguous umem as one DMA block and fault the kernel or NIC."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/umem.c","include/rdma/ib_umem.h"],"versions":[{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"3014da7587ce006cd08004fd6b257626b314e0a3","status":"affected","versionType":"git"},{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"ddccf6cc3861de2fe60986933bead79220e0d797","status":"affected","versionType":"git"},{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"e9bbb5f5349ef560ff6f0395564f04c3aa664559","status":"affected","versionType":"git"},{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"ae3cf7d2c4d506c5c91746321644e1a08d989e2a","status":"affected","versionType":"git"},{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"5fc5b73109540809b094710fac44da81dd8a3ff8","status":"affected","versionType":"git"},{"version":"a40c20dabdf9045270767c75918feb67f0727c89","lessThan":"09ea6837a0434fb4db99528a5055b6d822135dcf","status":"affected","versionType":"git"},{"version":"85e40ba1c4a5246b35e91c2ed69d4680426904d7","status":"affected","versionType":"git"},{"version":"59f07434b297e2268f5d5c567db5b09145245cf1","status":"affected","versionType":"git"},{"version":"488229b7729d7becf4c39c5e74fb709fb35115c2","status":"affected","versionType":"git"},{"version":"5.4.73","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.8.17","lessThan":"5.9","status":"affected","versionType":"semver"},{"version":"5.9.2","lessThan":"5.10","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/core/umem.c","include/rdma/ib_umem.h"],"versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.73"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8.17"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3014da7587ce006cd08004fd6b257626b314e0a3"},{"url":"https://git.kernel.org/stable/c/ddccf6cc3861de2fe60986933bead79220e0d797"},{"url":"https://git.kernel.org/stable/c/e9bbb5f5349ef560ff6f0395564f04c3aa664559"},{"url":"https://git.kernel.org/stable/c/ae3cf7d2c4d506c5c91746321644e1a08d989e2a"},{"url":"https://git.kernel.org/stable/c/5fc5b73109540809b094710fac44da81dd8a3ff8"},{"url":"https://git.kernel.org/stable/c/09ea6837a0434fb4db99528a5055b6d822135dcf"}],"title":"RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz()","x_generator":{"engine":"bippy-1.2.0"}}}}