Skip to main content
Vulnerability Database/CVE-2026-98365

CVE-2026-98365: Linux Kernel RDMA/rxe Privilege Escalation

CVE-2026-98365 is a privilege escalation flaw in Linux kernel RDMA/rxe caused by integer overflow in mr_check_range() allowing out-of-bounds memory access. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-98365 Overview

CVE-2026-98365 is an integer overflow vulnerability in the Linux kernel's RDMA/rxe (Soft RoCE) driver. The flaw resides in mr_check_range(), which validates memory region (MR) boundaries using wraparound-prone arithmetic. A remote peer can craft an RDMA Write or Read RETH packet with an iova and length that wrap around the 64-bit address space, bypassing the bounds check. The subsequent call to rxe_mr_iova_to_index() produces a huge index that rxe_mr_copy_xarray() dereferences, triggering out-of-bounds read or write access to mr->page_info[]. The result is a kernel oops reachable by an unauthenticated remote attacker over the network.

Critical Impact

An unauthenticated remote peer can trigger kernel out-of-bounds memory access in the RDMA/rxe driver, causing a kernel oops and potential memory corruption on any host exposing a Soft RoCE endpoint.

Affected Products

  • Linux kernel versions containing the vulnerable mr_check_range() implementation in drivers/infiniband/sw/rxe/
  • Systems with the Soft RoCE (RXE) RDMA transport driver loaded
  • Distributions shipping unpatched upstream kernels prior to the fix commits

Discovery Timeline

  • 2026-10-06 - CVE-2026-98365 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98365

Vulnerability Analysis

The vulnerability lives in the mr_check_range() function in the Linux kernel's RDMA Soft RoCE (rxe) driver. The function validates that a requested I/O virtual address range [iova, iova+length) sits within a registered memory region. The original check uses the expression iova + length > mr->ibmr.iova + mr->ibmr.length, which is subject to 64-bit integer overflow.

When a remote peer sends an RDMA Extended Transport Header (RETH) with values such as iova=0xfffffffffffffff8 and length=8, the sum iova + length wraps to 0. The comparison then evaluates as if the range were valid. Control flow continues into rxe_mr_iova_to_index(), which computes a page index guarded only by a WARN_ON. The oversized index is passed to rxe_mr_copy_xarray(), which indexes mr->page_info[huge_idx] far beyond the allocated array, resulting in an out-of-bounds read or write and a kernel oops.

Root Cause

The root cause is unchecked integer overflow in boundary validation arithmetic. The additive comparison does not account for wraparound in 64-bit unsigned addition. The upstream fix rewrites the check in overflow-safe form: it first validates iova >= mr->ibmr.iova and length <= mr->ibmr.length, then performs the comparison iova - mr->ibmr.iova > mr->ibmr.length - length, where the subtractions are guaranteed not to underflow.

Attack Vector

Exploitation requires network reachability to a host exposing an RDMA/rxe endpoint. The attacker crafts an RDMA Write or Read request with a RETH whose iova and length fields sum to zero or another wrap-around value. No authentication or user interaction is required. Successful exploitation triggers a kernel oops in the receive path, resulting in denial of service, and may enable memory corruption of adjacent kernel data depending on heap layout.

The vulnerability is described in prose; see the referenced upstream commits for the complete patch diff: Linux Kernel Commit 2f3b705 and Linux Kernel Commit 3431f52.

Detection Methods for CVE-2026-98365

Indicators of Compromise

  • Kernel oops or panic messages referencing mr_check_range, rxe_mr_iova_to_index, or rxe_mr_copy_xarray in dmesg or /var/log/kern.log
  • WARN_ON traces originating from the rxe module indicating anomalously large page indices
  • Unexpected REMOTE_ACCESS_ERROR completions logged by RDMA peers after the patch is applied, indicating prior exploitation attempts
  • Unsolicited inbound RDMA traffic to hosts not expected to serve RDMA workloads

Detection Strategies

  • Inventory hosts with the rdma_rxe kernel module loaded using lsmod | grep rdma_rxe and prioritize them for patching and monitoring
  • Monitor kernel ring buffer and syslog pipelines for crash signatures tied to the rxe driver stack
  • Capture and inspect RoCEv2 traffic (UDP port 4791) for RETH fields where iova + length wraps the 64-bit boundary
  • Correlate kernel crash events with concurrent inbound RDMA flows from untrusted network segments

Monitoring Recommendations

  • Forward kernel logs to a centralized SIEM or data lake and alert on rxe-related oops traces
  • Baseline expected RDMA peer endpoints and alert on new or unexpected sources initiating RDMA operations
  • Track kernel module load events to detect unauthorized loading of rdma_rxe on hosts that do not require it
  • Enable kernel address sanitizer (KASAN) builds in test environments to surface out-of-bounds access during fuzzing

How to Mitigate CVE-2026-98365

Immediate Actions Required

  • Apply the upstream kernel patches from the referenced stable commits as soon as vendor-rebuilt kernels become available
  • Unload the rdma_rxe module on hosts that do not require Soft RoCE: modprobe -r rdma_rxe
  • Block inbound RoCEv2 traffic (UDP port 4791) at perimeter and segment firewalls where RDMA is not an operational requirement
  • Restrict RDMA endpoints to trusted, isolated network segments or VLANs

Patch Information

Upstream fixes are available in the following stable branch commits: Linux Kernel Commit 2f3b705, Linux Kernel Commit 3431f52, Linux Kernel Commit 5d9426a, Linux Kernel Commit b7d2118, and Linux Kernel Commit d10e2a0. After patching, mr_check_range() returns -EINVAL for crafted iova values and the responder reports REMOTE_ACCESS_ERROR instead of triggering the out-of-bounds access.

Workarounds

  • Blacklist the rdma_rxe module on systems that do not require software RDMA by adding blacklist rdma_rxe to /etc/modprobe.d/
  • Enforce host and network firewall rules that drop inbound RoCEv2 UDP/4791 from untrusted sources
  • Isolate RDMA fabrics on dedicated, physically or logically segmented networks with strict peer allowlists
bash
# Disable the Soft RoCE driver on hosts that do not need it
sudo modprobe -r rdma_rxe
echo "blacklist rdma_rxe" | sudo tee /etc/modprobe.d/blacklist-rdma_rxe.conf

# Block inbound RoCEv2 traffic at the host firewall
sudo iptables -A INPUT -p udp --dport 4791 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.