CVE-2026-98323: Linux
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.
Affected products
- Linux Linux: from 5.10.150, before 5.10.271 (fixed in 5.10.271); from 5.15.75, before 5.15.222 (fixed in 5.15.222); from 5.4.220, before 5.5 (fixed in 5.5); from 5.19.17, before 5.20 (fixed in 5.20); from 6.0.3, before 6.1 (fixed in 6.1); from 6.1, before 6.1.189 (fixed in 6.1.189); …
Published 2026-10-06. Last modified 2026-10-07.