KernelScan.io

CRITICAL

siw FragmentedHdr OOB

CVE-2026-98323

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.

02

Engine v0.7.0

Risk summary

A remote attacker who can send data over a TCP connection to a system running the software iWARP (siw) driver can trigger an out-of-bounds write in kernel memory by sending a fragmented RDMA header. No local privileges are required. The corruption can lead to kernel code execution, data tampering, or a system crash.

Affecteddrivers/infiniband/sw/siw/siw_qp_rx.c (RDMA/siw receive path)

Vulnerability analysis

The software iWARP receive path processes extended DDP/RDMAP headers that may arrive fragmented across multiple TCP callbacks. When calculating how many bytes to copy for the remaining header fragment, the code uses a fixed offset rather than the number of bytes already received, so the copy can exceed the header buffer and overwrite adjacent receive state. A later callback then interprets the corrupted state as a copy offset, producing an out-of-bounds write into kernel memory. The fix bounds the copy length by the actual number of header bytes still missing, preventing the overflow. Any attacker who can send data over a TCP connection to a system with the siw driver loaded and an active RDMA endpoint can trigger this — no local account or privileges are required.

03

BranchIntroducedFixed inPatch commit
5.105.10.1505.10.2712c6fbcf4bfac
5.155.15.755.15.222af9f5b474a26
5.45.4.2205.5262dcd809723
5.195.19.175.20eb4d7a946970
6.06.0.36.18628f8ebf416
6.1—6.1.189b72dcfb9bf1f
6.6—6.6.158e6bdfdf3bcb0
6.12—6.12.1129ff797e516db
6.18—6.18.54—
7.2—7.2.8—
mainline—7.3-rc4—