Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98323— RDMA/siw: Bound fragmented header copies by the remaining length

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: RDMA/siw:根据剩余长度限制分片头部的复制操作 函数可能在多个 TCP 回调中接收跨越多个数据分片(DDP/RDMAP)报头的扩展头部信息。第一个回调可能接收到头部的大部分数据,而下一个回调仍可能将复制长度限制为 ,而非实际缺失的字节数。这会导致目标指针超出头部末尾,从而覆盖接收状态(包括 字段)。后续的回调可能会将负值的 用作复制偏移量,从而导致越界写(OOB write)。 在计算下一次复制长度时,应使用已经接收到的头部字节数。

CVSS 9.8 · Critical EPSS 0.56% · P45

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 26

VendorProduct Version RangeStatus
Linux Linux e3917c85f41ef1df64e27dc0e46ab0d803c5e73e< 2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7 affected
308cd50f174c95a507527037f4de1a0396aa4325< af9f5b474a260ad23ffb9793d716a5e3bbce3b48 affected
754209850df8367c954ac1de7671c7430b1f342c< 262dcd809723723ed8a4e05437ec7e9c21a8f17e affected
754209850df8367c954ac1de7671c7430b1f342c< eb4d7a946970469b3ab0c762432bf161d5b0836c affected
754209850df8367c954ac1de7671c7430b1f342c< 8628f8ebf41669302513fb3f0bf0eba38b226742 affected
754209850df8367c954ac1de7671c7430b1f342c< b72dcfb9bf1f0f0147cda03dc59e4002a315067f affected
754209850df8367c954ac1de7671c7430b1f342c< e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d affected
754209850df8367c954ac1de7671c7430b1f342c< 9ff797e516dbc1ecb73701ec4c24055712d44411 affected
… +18 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98323

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/siw: Bound fragmented header copies by the remaining length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e3917c85f41ef1df64e27dc0e46ab0d803c5e73e ~ 2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7 -
Linux Linux 6.1 -

II. Public POCs for CVE-2026-98323

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98323

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98323 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98311 7.8 HIGH wifi: virt_wifi: don't transfer operstate before register
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98323

No comments yet


Leave a comment