{"id":"CVE-2026-97413","published":"2026-09-24T17:17:18.990","lastModified":"2026-09-25T13:17:24.830","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Fix integer underflow in process_read and process_write\n\nusr_len is read from a network-supplied message field (le16_to_cpu)\nand used to compute data_len = off - usr_len without validating that\nusr_len <= off. A malicious RDMA client can send usr_len > off causing\nan integer underflow, resulting in data_len wrapping to a huge size_t\nvalue which is then passed to the rdma_ev callback as a memory length,\nleading to out-of-bounds memory access.\n\nFix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids()\nin both process_read() and process_write(), ensuring the early return\npath acquires no reference and has no resource leak.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/24ad03bfeda05fca04c56677e57fd3d6bc3e9978","tags":[]},{"url":"https://git.kernel.org/stable/c/54bf38b27afc08a0eb6b732f9c14eb8a4bcb66b5","tags":[]},{"url":"https://git.kernel.org/stable/c/c76e9123ab91a903396d26e6ab1b5caae5c6b149","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw involves an integer underflow in the RDMA/rtrs-srv process_read and process_write functions, allowing a malicious client to cause out-of-bounds memory access. It matters because it can lead to severe system instability or potential privilege escalation.","exploitability":"Exploitation requires a malicious RDMA client with network access. The vulnerability is hard to exploit due to the need for precise control over the network message fields.","blast_radius":"If exploited, this could result in unauthorized access to sensitive system memory, potentially leading to system compromise or data leakage.","remediation":"Upgrade to the Linux kernel version 6.1.17 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rdma","memory-access","kernel","critical"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:52:29.770Z"}}