9.1
CRITICAL CVSS 3.1
CVE-2026-64269
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read()), so desc[0].len is attacker-controlled and, before this change, was only rejected when zero. The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size. msg_id and off are bounded against queue_depth and max_chunk_size in rtrs_srv_rdma_done(), but desc[0].len is a separate field that was not checked against the chunk size. A peer that advertises desc[0].len larger than max_chunk_size can make the posted RDMA write read past the chunk's mapped region. The resulting behaviour depends on the IOMMU configuration: with no IOMMU or in passthrough mode the read may extend into memory adjacent to the chunk and be returned to the peer, which can disclose host memory; with a translating IOMMU the out-of-range access is expected to fault and abort the connection. In either case the transfer exceeds what the protocol permits and is driven by a remote peer. Reject a descriptor length above max_chunk_size, mirroring the existing off >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients do not exceed it: the client sets desc[0].len to its MR length, which is capped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE).

INFO

Published Date :

July 25, 2026, 10:17 a.m.

Last Modified :

Aug. 17, 2026, 5:17 a.m.

Remotely Exploit :

Yes !

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64269 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Fix Linux kernel vulnerability by validating RDMA write lengths against chunk size.
  • Update the Linux kernel to the latest security patch.
  • Validate RDMA write lengths against the chunk size.
  • Reject descriptor lengths exceeding the maximum chunk size.
  • Ensure client MR lengths do not exceed negotiated limits.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64269 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64269 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64269 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64269 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}]
  • Initial Analysis by [email protected]

    Aug. 13, 2026

    Action Type Old Value New Value
    Added CWE NVD-CWE-noinfo
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.178 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.145 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.96 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.39 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.1.4 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.8 up to (excluding) 5.15.212
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 27, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 25, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read()), so desc[0].len is attacker-controlled and, before this change, was only rejected when zero. The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size. msg_id and off are bounded against queue_depth and max_chunk_size in rtrs_srv_rdma_done(), but desc[0].len is a separate field that was not checked against the chunk size. A peer that advertises desc[0].len larger than max_chunk_size can make the posted RDMA write read past the chunk's mapped region. The resulting behaviour depends on the IOMMU configuration: with no IOMMU or in passthrough mode the read may extend into memory adjacent to the chunk and be returned to the peer, which can disclose host memory; with a translating IOMMU the out-of-range access is expected to fault and abort the connection. In either case the transfer exceeds what the protocol permits and is driven by a remote peer. Reject a descriptor length above max_chunk_size, mirroring the existing off >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients do not exceed it: the client sets desc[0].len to its MR length, which is capped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE).
    Added Reference https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc
    Added Reference https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667
    Added Reference https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb
    Added Reference https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da
    Added Reference https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66
    Added Reference https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1
    Added Reference https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.