Database/Kernel, userspace & hypervisor
Linux kernel SoftiWARP transmit path (siw_qp_tx, siw_tcp_sendpages byte accounting): After do_tcp_sendpages() was
Impact
After do_tcp_sendpages() was inlined, the sendmsg byte count passed for each page no longer matched the bvec length actually set up, so the transmit path pushed the wrong number of bytes per page. Wrong-length sends on a zero-copy RDMA transmit path mean bytes adjacent to the intended payload go onto the wire, and the stream desynchronises against what the peer expects. The kernel CNA scores it network-reachable with full confidentiality and integrity impact.
Who can reach it
Remote-facing. The corruption occurs on data leaving the node over an established SoftiWARP connection, so a peer that can induce the pathological send pattern observes the extra bytes.
What to do
Kernel update correcting the byte count in siw_tcp_sendpages(). Unload siw where it is not required.
References
Related entries
- Linux kernel (net/tls): When the socket buffer is too small to hold a whole record, kTLS parses early and re-parses asCVE-2025-39946 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLSCVE-2025-40176 · Linux kernel (net/tls)Critical
- Linux kernel mlx5_core RX datapath (striding RQ + XDP multi-buffer): The mlx5 driver assumed an XDP program couldCVE-2025-40350 · Linux kernel mlx5_core RX datapath (striding RQ + XDP multi-buffer)Critical
- Linux kernel iomap: length underflow on non-block-aligned reads returns a position past the folioCVE-2025-68794 · Linux kernel iomap (iomap_adjust_read_range block alignment)Critical
- Linux kernel (net/tls): Closing a kTLS socket cancelled the transmit work item, but the write-space callback couldCVE-2026-23240 · Linux kernel (net/tls)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.