GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel RDMA/siw: out-of-bounds write from fragmented DDP/RDMAP header copies

UnscoredCVE-2026-98323Firmware, BMC & network fabriccurated

Impact

siw is the software iWARP RDMA provider, used where RDMA verbs are needed without RoCE/InfiniBand hardware - storage clients, NVMe-oF, and RDMA test or fallback paths on GPU nodes. When an extended DDP/RDMAP header arrives split across more than one TCP callback, the second copy is sized from the full header length instead of the bytes still missing, so the copy runs past the end of the header and corrupts the receive state structure, including fpdu_part_rcvd. A later callback then uses a negative fpdu_part_rcvd as a copy offset, giving an out-of-bounds write driven by data on the wire. The input is attacker-controlled TCP segmentation against a listening siw endpoint, which makes this the rarer kind of kernel bug that is reachable remotely rather than only locally. No CVSS score, CWE or vendor advisory is attached to the record - only the stable-tree fixes.

Who can reach it

Anyone who can open a TCP connection to a siw RDMA endpoint, or who sits in the network path and controls segmentation, with no authentication at the RDMA transport layer. Only nodes that actually load the siw module and expose an iWARP listener are affected; fleets using mlx5 RoCE/InfiniBand hardware without siw are not.

What to do

Pick up the fixed stable kernel and reboot each affected node - this is kernel receive-path code, so there is no hot-patch or module-reload path that is safe while connections are live. On GPU nodes that means a drain and reboot cycle per node. If siw is not in use, unloading or blacklisting the siw module removes the exposure without a reboot. The record names no fixed version numbers beyond the stable commits.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.