« Volver al listado

CVE-2026-98323

Estado: RecibidaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Bound fragmented header copies by the remaining length

siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write.

Leer descripción completaMostrar menos

Use the number of header bytes already received when calculating the next copy length.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N indica explotación remota sin autenticación (T1190). El buffer overflow en siw_get_hdr() permite escritura fuera de límites que corrompe el estado de recepción, permitiendo acceso a memoria de kernel y potencial escalada de privilegios (T1068) o negación de servicio (T1499

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98323",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e3917c85f41ef1df64e27dc0e46ab0d803c5e73e",
              "lessThan": "2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "308cd50f174c95a507527037f4de1a0396aa4325",
              "lessThan": "af9f5b474a260ad23ffb9793d716a5e3bbce3b48",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "262dcd809723723ed8a4e05437ec7e9c21a8f17e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "eb4d7a946970469b3ab0c762432bf161d5b0836c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "8628f8ebf41669302513fb3f0bf0eba38b226742",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "b72dcfb9bf1f0f0147cda03dc59e4002a315067f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "lessThan": "9ff797e516dbc1ecb73701ec4c24055712d44411",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e09caa38e10bcf027100cc22b0e3cc745a39ef0a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0c14f795a9eab9344230f9933798b8ee496f497d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fada7c6962219b6fc4ff4e62e46a936af110dd9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.150",
              "lessThan": "5.10.271",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.75",
              "lessThan": "5.15.222",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.220",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.19.17",
              "lessThan": "5.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.0.3",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_qp_rx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_qp_rx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:24.403",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/262dcd809723723ed8a4e05437ec7e9c21a8f17e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8628f8ebf41669302513fb3f0bf0eba38b226742",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9ff797e516dbc1ecb73701ec4c24055712d44411",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af9f5b474a260ad23ffb9793d716a5e3bbce3b48",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b72dcfb9bf1f0f0147cda03dc59e4002a315067f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eb4d7a946970469b3ab0c762432bf161d5b0836c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Bound fragmented header copies by the remaining length\n\nsiw_get_hdr() can receive an extended DDP/RDMAP header across more than\none TCP callback. The first callback may receive most of the header,\nwhile the next one still limits the copy to hdrlen - MIN_DDP_HDR instead\nof the number of missing bytes. This makes the destination move past the\nend of the header and overwrite the receive state, including\nfpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd\nvalue as a copy offset, which creates an OOB write.\n\nUse the number of header bytes already received when calculating the\nnext copy length."
    }
  ],
  "lastModified": "2026-10-07T07:17:08.990",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}