{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98365","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.344Z","datePublished":"2026-10-06T08:46:50.834Z","dateUpdated":"2026-10-07T06:50:18.479Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:50:18.479Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access\n\nmr_check_range() validates that [iova, iova+length) falls within the\nregistered MR range using wraparound-prone arithmetic:\n\n    if (iova < mr->ibmr.iova ||\n        iova + length > mr->ibmr.iova + mr->ibmr.length)\n\nA remote peer can craft an RDMA-Write/Read RETH so that iova + length\nwraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the\ncheck. rxe_mr_iova_to_index() then computes a huge index (int idx, only\nguarded by WARN_ON) and rxe_mr_copy_xarray() dereferences\nmr->page_info[huge], causing an out-of-bounds read/write and a kernel\noops that is triggerable by an unauthenticated remote peer.\n\nRewrite the check in overflow-safe form; the first two clauses guarantee\nthat the subsequent subtractions do not underflow:\n\n    if (iova < mr->ibmr.iova ||\n        length > mr->ibmr.length ||\n        iova - mr->ibmr.iova > mr->ibmr.length - length)\n\nWith the fix, mr_check_range() returns -EINVAL for the crafted iova and\nthe responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bad iova and length come from the RETH header of a RoCEv2 RDMA WRITE/READ (UDP/IP, routable). qp_resp_from_reth() copies them into qp->resp, and check_rkey() hands them to mr_check_range(), where iova+length wraps past 2^64 and the bounds check passes.\nAC:L - The attacker is the connected RC peer, so it controls the QPN, PSN and RETH contents and chooses va near 2^64 to make iova+length wrap for any MR. The bug fires on the first packet, with no race or memory layout to win.\nPR:N - RoCE has no authentication. check_addr() only matches the peer's IP address, and services such as rtrs-srv send MR rkeys with IB_ACCESS_REMOTE_WRITE to any client that connects, without checking credentials.\nUI:N - No victim action is needed. The responder processes the attacker's RETH request entirely in kernel receive context once the QP is connected.\nS:U - The out-of-bounds access corrupts or discloses kernel memory on the same host, inside the kernel's own security authority. No VM or IOMMU boundary is crossed.\nC:H - For RDMA READ, rxe_mr_copy_xarray() memcpy()s from a struct page pointer read out of bounds of mr->page_info[], and that data is sent back to the remote peer. Choosing va moves the index over a window of about 2^20 entries.\nI:H - For RDMA WRITE, rxe_mr_copy_xarray() memcpy()s the peer's payload into the page pointed to by the out-of-bounds page_info[idx].page entry. That is a remote write into kernel-chosen memory, which can be used to hijack control flow.\nA:H - An out-of-bounds page_info index, past the WARN_ON in rxe_mr_iova_to_index(), dereferences garbage page pointers and oopses the kernel. A remote peer can repeat this at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mr.c"],"versions":[{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"b7d2118660545a00b21e83010ded1a231c6fb8c5","status":"affected","versionType":"git"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"5d9426a74fc8cb8f375fcdc19b465a030f9b8cab","status":"affected","versionType":"git"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"2f3b705144e3a3c14184fec6e354680081fe91ec","status":"affected","versionType":"git"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"3431f525718f6b07da308cda6d44f8cb548bbd37","status":"affected","versionType":"git"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"d10e2a08799e858d3e71ea4169bcd018f216d444","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mr.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b7d2118660545a00b21e83010ded1a231c6fb8c5"},{"url":"https://git.kernel.org/stable/c/5d9426a74fc8cb8f375fcdc19b465a030f9b8cab"},{"url":"https://git.kernel.org/stable/c/2f3b705144e3a3c14184fec6e354680081fe91ec"},{"url":"https://git.kernel.org/stable/c/3431f525718f6b07da308cda6d44f8cb548bbd37"},{"url":"https://git.kernel.org/stable/c/d10e2a08799e858d3e71ea4169bcd018f216d444"}],"title":"RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access","x_generator":{"engine":"bippy-1.2.0"}}}}