CRITICAL
siw FragmentedHdr OOB
CVE-2026-98323
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.8CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.
02KernelScan AI Analysis
Risk summary
A remote attacker who can send data over a TCP connection to a system running the software iWARP (siw) driver can trigger an out-of-bounds write in kernel memory by sending a fragmented RDMA header. No local privileges are required. The corruption can lead to kernel code execution, data tampering, or a system crash.
Vulnerability analysis
The software iWARP receive path processes extended DDP/RDMAP headers that may arrive fragmented across multiple TCP callbacks. When calculating how many bytes to copy for the remaining header fragment, the code uses a fixed offset rather than the number of bytes already received, so the copy can exceed the header buffer and overwrite adjacent receive state. A later callback then interprets the corrupted state as a copy offset, producing an out-of-bounds write into kernel memory. The fix bounds the copy length by the actual number of header bytes still missing, preventing the overflow. Any attacker who can send data over a TCP connection to a system with the siw driver loaded and an active RDMA endpoint can trigger this — no local account or privileges are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 5.10.150 | 5.10.271 | 2c6fbcf4bfac |
| 5.15 | 5.15.75 | 5.15.222 | af9f5b474a26 |
| 5.4 | 5.4.220 | 5.5 | 262dcd809723 |
| 5.19 | 5.19.17 | 5.20 | eb4d7a946970 |
| 6.0 | 6.0.3 | 6.1 | 8628f8ebf416 |
| 6.1 | — | 6.1.189 | b72dcfb9bf1f |
| 6.6 | — | 6.6.158 | e6bdfdf3bcb0 |
| 6.12 | — | 6.12.112 | 9ff797e516db |
| 6.18 | — | 6.18.54 | — |
| 7.2 | — | 7.2.8 | — |
| mainline | — | 7.3-rc4 | — |