← All Advisories

CVE-2026-98323

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98323

Key Details

CVECVE-2026-98323
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Bound fragmented header copies by the remaining length

siw_get_hdr() can receive an extended DDP/RDMAP header across more than

one TCP callback. The first callback may receive most of the header,

while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead

of the number of missing bytes. This makes the destination move past the

end of the header and overwrite the receive state, including

fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd

value as a copy offset, which creates an OOB write.

Use the number of header bytes already received when calculating the

next copy length. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98323
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98323