GPU VulnDB

Database/Firmware, BMC & network fabric

Linux kernel soft-RoCE: integer overflow in MR range check gives a remote peer out-of-bounds kernel access

CVSS 9.8CVE-2026-98365Firmware, BMC & network fabriccurated

Impact

A peer on the RDMA network can craft an RDMA Write/Read RETH header whose iova + length wraps past 2^64, slipping past the memory-region bounds check in mr_check_range(). The responder then computes an enormous page index - guarded only by a WARN_ON - and reads or writes outside mr->page_info, giving an out-of-bounds kernel read/write and an oops. No authentication beyond reachability of the RDMA port is needed, so on a fabric that carries traffic for more than one tenant this is remote denial of service of the node and a plausible path to kernel memory corruption. This affects the software RoCE driver (rxe), not the hardware mlx5 path: fleets that do RDMA only through ConnectX/BlueField HCAs and never load the rdma_rxe module are not exposed, while clusters that use soft-RoCE for testing, storage clients or CPU-side nodes are.

Who can reach it

Any host that can send RDMA packets to a node with the rdma_rxe module loaded and a registered memory region - typically anyone on the storage or compute fabric. No authentication, no prior queue-pair credentials beyond what a normal RoCE peer holds.

What to do

Take the stable kernel fix (five stable branches carry it; see the git.kernel.org commits) and reboot each affected node - a kernel change on the RDMA path cannot be hot-patched in place, so this is a drain-and-reboot pass across the fleet. Where soft-RoCE is not actually needed, the cheaper interim step is to confirm rdma_rxe is not loaded and blacklist it; nodes doing RDMA purely through hardware HCAs need no action. No vendor advisory beyond the kernel commits was in the record, so no single fixed release number is quoted here.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.