In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer...

zetlyn/cve-ghsa vulnerability ghsa GHSA-wv45-qhgq-9h5f cve CVE-2026-97413 known 2026-09-24

https://github.com/advisories/GHSA-wv45-qhgq-9h5f

Properties

cvss9.8
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

severitycritical
GitHub's own rating, from the CVSS base score at 9.0 and above.
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

Text

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer... In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len <= off. A malicious RDMA client can send usr_len > off causing an integer underflow, resulting in data_len wrapping to a huge size_t value which is then passed to the rdma_ev callback as a memory length, leading to out-of-bounds memory access. Fix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids() in both process_read() and process_write(), ensuring the early return path acquires no reference and has no resource leak.