CRITICAL Introduced in 4.8
rxe RangeCheck Overflow
CVE-2026-98365
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.8CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: if (iova < mr->ibmr.iova || iova + length > mr->ibmr.iova + mr->ibmr.length) A remote peer can craft an RDMA-Write/Read RETH so that iova + length wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the check. rxe_mr_iova_to_index() then computes a huge index (int idx, only guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences mr->page_info[huge], causing an out-of-bounds read/write and a kernel oops that is triggerable by an unauthenticated remote peer. Rewrite the check in overflow-safe form; the first two clauses guarantee that the subsequent subtractions do not underflow: if (iova < mr->ibmr.iova || length > mr->ibmr.length || iova - mr->ibmr.iova > mr->ibmr.length - length) With the fix, mr_check_range() returns -EINVAL for the crafted iova and the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker who can reach a host running the Soft RoCE (RXE) driver can send a crafted RDMA packet that bypasses memory-region bounds checking via an integer overflow. This leads to an out-of-bounds kernel memory access that can crash the system or potentially corrupt or disclose kernel memory. Any device with RXE configured and its RDMA UDP port (4791) exposed to the network is at risk.
Vulnerability analysis
The Soft RoCE driver validates incoming RDMA operation addresses against a registered memory region using arithmetic that can silently wrap around: when a remote peer supplies an address and size whose sum overflows a 64-bit integer, the upper-bound check passes even though the range is entirely outside the registered region. The driver then translates the bogus address into a huge array index and dereferences it, causing an out-of-bounds kernel memory access that can crash the system or corrupt memory. The fix rewrites the bounds check so that each comparison is performed with overflow-safe subtractions, and any crafted range is rejected before the index is computed. The vulnerable path is reachable by any remote peer who can send UDP packets to the target's RoCEv2 port; no authentication or local access is required, though the RXE kernel module must be loaded and bound to a network device.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | 4.8 | 6.6.158 | b7d211866054 |
| 6.12 | 4.8 | 6.12.112 | 5d9426a74fc8 |
| 6.18 | 4.8 | 6.18.54 | 2f3b705144e3 |
| 7.2 | 4.8 | 7.2.8 | 3431f525718f |
| mainline | 4.8 | 7.3-rc4 | d10e2a08799e |