CVE-2026-98365

Source
https://cve.org/CVERecord?id=CVE-2026-98365
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98365.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98365
Downstream
Published
2026-10-06T08:46:50Z
Modified
2026-10-07T02:47:30Z
Summary
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access

mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic:

if (iova < mr->ibmr.iova ||
    iova + length > mr->ibmr.iova + mr->ibmr.length)

A remote peer can craft an RDMA-Write/Read RETH so that iova + length wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the check. rxe_mr_iova_to_index() then computes a huge index (int idx, only guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences mr->page_info[huge], causing an out-of-bounds read/write and a kernel oops that is triggerable by an unauthenticated remote peer.

Rewrite the check in overflow-safe form; the first two clauses guarantee that the subsequent subtractions do not underflow:

if (iova < mr->ibmr.iova ||
    length > mr->ibmr.length ||
    iova - mr->ibmr.iova > mr->ibmr.length - length)

With the fix, mr_check_range() returns -EINVAL for the crafted iova and the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98365.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8700e3e7c4857d28ebaa824509934556da0b3e76
Fixed
b7d2118660545a00b21e83010ded1a231c6fb8c5
Fixed
5d9426a74fc8cb8f375fcdc19b465a030f9b8cab
Fixed
2f3b705144e3a3c14184fec6e354680081fe91ec
Fixed
3431f525718f6b07da308cda6d44f8cb548bbd37
Fixed
d10e2a08799e858d3e71ea4169bcd018f216d444

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98365.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98365.json"