KernelScan.io

CRITICAL Introduced in 5.8

rtrs-srv UsrLen Underflow

CVE-2026-97413

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len <= off. A malicious RDMA client can send usr_len > off causing an integer underflow, resulting in data_len wrapping to a huge size_t value which is then passed to the rdma_ev callback as a memory length, leading to out-of-bounds memory access. Fix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids() in both process_read() and process_write(), ensuring the early return path acquires no reference and has no resource leak.

02

Engine v0.6.0

Risk summary

A malicious RDMA client can send a crafted message to an RTRS server causing an integer underflow in the data length computation, leading to out-of-bounds kernel memory access. This can result in information disclosure, memory corruption, or kernel crash. Any product running the rtrs-srv module with an accessible RDMA fabric is at risk.

Affecteddrivers/infiniband/ulp/rtrs/rtrs-srv.c (RDMA RTRS server)

Vulnerability analysis

The RTRS server reads a user-supplied length field from incoming RDMA messages and subtracts it from an internal offset to compute a data length, but never checks that the supplied value is within bounds. A malicious RDMA client can send a value larger than the offset, causing the subtraction to wrap around to an enormous unsigned value. This wrapped value is then passed as a memory length to an internal callback, causing the kernel to access memory far beyond the intended buffer. The fix moves the length read earlier in both the read and write processing paths and rejects any message where the supplied length exceeds the offset, returning before any resources are acquired. The attacker only needs to be an RDMA client that can connect to the server — no privileges or authentication are required, though the target must have the rtrs-srv module loaded and RDMA hardware configured.

03

BranchIntroducedFixed inPatch commit
6.125.86.12.11124ad03bfeda0
6.185.86.18.53c76e9123ab91
mainline5.87.254bf38b27afc