CVE-2026-64269

Source
https://cve.org/CVERecord?id=CVE-2026-64269
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64269.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64269
Downstream
Published
2026-07-25T08:49:16.946Z
Modified
2026-07-27T04:03:20.881902860Z
Summary
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdmawritesg

When the server answers an RTRS READ, rdmawritesg() builds the source scatter/gather entry for the IBWRRDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor:

plist->length = le32tocpu(id->rd_msg->desc[0].len);

rdmsg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrssrvrdmadone() -> processioreq() -> processread()), so desc[0].len is attacker-controlled and, before this change, was only rejected when zero. The source address is the fixed chunk start (dmaaddr[msgid]) and the source lkey is the PD-wide localdmalkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to maxchunksize. msgid and off are bounded against queuedepth and maxchunksize in rtrssrvrdmadone(), but desc[0].len is a separate field that was not checked against the chunk size.

A peer that advertises desc[0].len larger than maxchunksize can make the posted RDMA write read past the chunk's mapped region. The resulting behaviour depends on the IOMMU configuration: with no IOMMU or in passthrough mode the read may extend into memory adjacent to the chunk and be returned to the peer, which can disclose host memory; with a translating IOMMU the out-of-range access is expected to fault and abort the connection. In either case the transfer exceeds what the protocol permits and is driven by a remote peer.

Reject a descriptor length above maxchunksize, mirroring the existing off >= maxchunksize bound in rtrssrvrdmadone(). Legitimate clients do not exceed it: the client sets desc[0].len to its MR length, which is capped at the negotiated maxiosize (maxchunksize - MAXHDR_SIZE).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64269.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9cb837480424e78ed585376f944088246685aec3
Fixed
68c09762172f6224e9ddf9b0a60bacbb36e443eb
Fixed
6cada540150894e81042a0ae0c796a21a9a877da
Fixed
2912f3d40355dabc08fdbaaf2764d02445fe88dc
Fixed
6f40246f4312fdbab5a13cc440adebf95eb2aa66
Fixed
5a45d0aa1fa50a333ce5763ade744e2d89838667
Fixed
da3e44add94b05dfde56f898421922f5cf35705f
Fixed
963af8d97a8c6a117134a8d0db1415e0489200b1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64269.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64269.json"