CVE-2026-98365 Overview
CVE-2026-98365 is an integer overflow vulnerability in the Linux kernel's RDMA/rxe (Soft RoCE) driver. The flaw resides in mr_check_range(), which validates memory region (MR) boundaries using wraparound-prone arithmetic. A remote peer can craft an RDMA Write or Read RETH packet with an iova and length that wrap around the 64-bit address space, bypassing the bounds check. The subsequent call to rxe_mr_iova_to_index() produces a huge index that rxe_mr_copy_xarray() dereferences, triggering out-of-bounds read or write access to mr->page_info[]. The result is a kernel oops reachable by an unauthenticated remote attacker over the network.
Critical Impact
An unauthenticated remote peer can trigger kernel out-of-bounds memory access in the RDMA/rxe driver, causing a kernel oops and potential memory corruption on any host exposing a Soft RoCE endpoint.
Affected Products
- Linux kernel versions containing the vulnerable mr_check_range() implementation in drivers/infiniband/sw/rxe/
- Systems with the Soft RoCE (RXE) RDMA transport driver loaded
- Distributions shipping unpatched upstream kernels prior to the fix commits
Discovery Timeline
- 2026-10-06 - CVE-2026-98365 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98365
Vulnerability Analysis
The vulnerability lives in the mr_check_range() function in the Linux kernel's RDMA Soft RoCE (rxe) driver. The function validates that a requested I/O virtual address range [iova, iova+length) sits within a registered memory region. The original check uses the expression iova + length > mr->ibmr.iova + mr->ibmr.length, which is subject to 64-bit integer overflow.
When a remote peer sends an RDMA Extended Transport Header (RETH) with values such as iova=0xfffffffffffffff8 and length=8, the sum iova + length wraps to 0. The comparison then evaluates as if the range were valid. Control flow continues into rxe_mr_iova_to_index(), which computes a page index guarded only by a WARN_ON. The oversized index is passed to rxe_mr_copy_xarray(), which indexes mr->page_info[huge_idx] far beyond the allocated array, resulting in an out-of-bounds read or write and a kernel oops.
Root Cause
The root cause is unchecked integer overflow in boundary validation arithmetic. The additive comparison does not account for wraparound in 64-bit unsigned addition. The upstream fix rewrites the check in overflow-safe form: it first validates iova >= mr->ibmr.iova and length <= mr->ibmr.length, then performs the comparison iova - mr->ibmr.iova > mr->ibmr.length - length, where the subtractions are guaranteed not to underflow.
Attack Vector
Exploitation requires network reachability to a host exposing an RDMA/rxe endpoint. The attacker crafts an RDMA Write or Read request with a RETH whose iova and length fields sum to zero or another wrap-around value. No authentication or user interaction is required. Successful exploitation triggers a kernel oops in the receive path, resulting in denial of service, and may enable memory corruption of adjacent kernel data depending on heap layout.
The vulnerability is described in prose; see the referenced upstream commits for the complete patch diff: Linux Kernel Commit 2f3b705 and Linux Kernel Commit 3431f52.
Detection Methods for CVE-2026-98365
Indicators of Compromise
- Kernel oops or panic messages referencing mr_check_range, rxe_mr_iova_to_index, or rxe_mr_copy_xarray in dmesg or /var/log/kern.log
- WARN_ON traces originating from the rxe module indicating anomalously large page indices
- Unexpected REMOTE_ACCESS_ERROR completions logged by RDMA peers after the patch is applied, indicating prior exploitation attempts
- Unsolicited inbound RDMA traffic to hosts not expected to serve RDMA workloads
Detection Strategies
- Inventory hosts with the rdma_rxe kernel module loaded using lsmod | grep rdma_rxe and prioritize them for patching and monitoring
- Monitor kernel ring buffer and syslog pipelines for crash signatures tied to the rxe driver stack
- Capture and inspect RoCEv2 traffic (UDP port 4791) for RETH fields where iova + length wraps the 64-bit boundary
- Correlate kernel crash events with concurrent inbound RDMA flows from untrusted network segments
Monitoring Recommendations
- Forward kernel logs to a centralized SIEM or data lake and alert on rxe-related oops traces
- Baseline expected RDMA peer endpoints and alert on new or unexpected sources initiating RDMA operations
- Track kernel module load events to detect unauthorized loading of rdma_rxe on hosts that do not require it
- Enable kernel address sanitizer (KASAN) builds in test environments to surface out-of-bounds access during fuzzing
How to Mitigate CVE-2026-98365
Immediate Actions Required
- Apply the upstream kernel patches from the referenced stable commits as soon as vendor-rebuilt kernels become available
- Unload the rdma_rxe module on hosts that do not require Soft RoCE: modprobe -r rdma_rxe
- Block inbound RoCEv2 traffic (UDP port 4791) at perimeter and segment firewalls where RDMA is not an operational requirement
- Restrict RDMA endpoints to trusted, isolated network segments or VLANs
Patch Information
Upstream fixes are available in the following stable branch commits: Linux Kernel Commit 2f3b705, Linux Kernel Commit 3431f52, Linux Kernel Commit 5d9426a, Linux Kernel Commit b7d2118, and Linux Kernel Commit d10e2a0. After patching, mr_check_range() returns -EINVAL for crafted iova values and the responder reports REMOTE_ACCESS_ERROR instead of triggering the out-of-bounds access.
Workarounds
- Blacklist the rdma_rxe module on systems that do not require software RDMA by adding blacklist rdma_rxe to /etc/modprobe.d/
- Enforce host and network firewall rules that drop inbound RoCEv2 UDP/4791 from untrusted sources
- Isolate RDMA fabrics on dedicated, physically or logically segmented networks with strict peer allowlists
# Disable the Soft RoCE driver on hosts that do not need it
sudo modprobe -r rdma_rxe
echo "blacklist rdma_rxe" | sudo tee /etc/modprobe.d/blacklist-rdma_rxe.conf
# Block inbound RoCEv2 traffic at the host firewall
sudo iptables -A INPUT -p udp --dport 4791 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.