← Back to search

CVE-2026-97413

9.8 CRITICAL

Published 2026-09-24 · Updated 2026-09-25

AI risk analysis

Summary
This flaw involves an integer underflow in the RDMA/rtrs-srv process_read and process_write functions, allowing a malicious client to cause out-of-bounds memory access. It matters because it can lead to severe system instability or potential privilege escalation.
Exploitability
Exploitation requires a malicious RDMA client with network access. The vulnerability is hard to exploit due to the need for precise control over the network message fields.
Blast radius
If exploited, this could result in unauthorized access to sensitive system memory, potentially leading to system compromise or data leakage.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the Linux kernel version 6.1.17 or later.
rdmamemory-accesskernelcritical

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len <= off. A malicious RDMA client can send usr_len > off causing an integer underflow, resulting in data_len wrapping to a huge size_t value which is then passed to the rdma_ev callback as a memory length, leading to out-of-bounds memory access. Fix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids() in both process_read() and process_write(), ensuring the early return path acquires no reference and has no resource leak.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.