CVE-2026-64269
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read()), so desc[0].len is attacker-controlled and, before this change, was only rejected when zero. The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size. msg_id and off are bounded against queue_depth and max_chunk_size in rtrs_srv_rdma_done(), but desc[0].len is a separate field that was not checked against the chunk size. A peer that advertises desc[0].len larger than max_chunk_size can make the posted RDMA write read past the chunk's mapped region. The resulting behaviour depends on the IOMMU configuration: with no IOMMU or in passthrough mode the read may extend into memory adjacent to the chunk and be returned to the peer, which can disclose host memory; with a translating IOMMU the out-of-range access is expected to fault and abort the connection. In either case the transfer exceeds what the protocol permits and is driven by a remote peer. Reject a descriptor length above max_chunk_size, mirroring the existing off >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients do not exceed it: the client sets desc[0].len to its MR length, which is capped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE).
INFO
Published Date :
July 25, 2026, 10:17 a.m.
Last Modified :
Aug. 17, 2026, 5:17 a.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to the latest security patch.
- Validate RDMA write lengths against the chunk size.
- Reject descriptor lengths exceeding the maximum chunk size.
- Ensure client MR lengths do not exceed negotiated limits.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-64269.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-64269 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-64269
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-64269 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-64269 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}] -
Initial Analysis by [email protected]
Aug. 13, 2026
Action Type Old Value New Value Added CWE NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.178 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.145 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.96 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.39 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.1.4 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.8 up to (excluding) 5.15.212 Added Reference Type kernel.org: https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jul. 27, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jul. 25, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '68c09762172f6224e9ddf9b0a60bacbb36e443eb', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6cada540150894e81042a0ae0c796a21a9a877da', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '2912f3d40355dabc08fdbaaf2764d02445fe88dc', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '6f40246f4312fdbab5a13cc440adebf95eb2aa66', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '5a45d0aa1fa50a333ce5763ade744e2d89838667', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': 'da3e44add94b05dfde56f898421922f5cf35705f', 'versionType': 'git'}, {'status': 'affected', 'version': '9cb837480424e78ed585376f944088246685aec3', 'lessThan': '963af8d97a8c6a117134a8d0db1415e0489200b1', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.8'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.8', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.96', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.39', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.4', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/ulp/rtrs/rtrs-srv.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length is taken directly from the wire descriptor: plist->length = le32_to_cpu(id->rd_msg->desc[0].len); rd_msg points into the chunk buffer that the remote peer filled via RDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() -> process_read()), so desc[0].len is attacker-controlled and, before this change, was only rejected when zero. The source address is the fixed chunk start (dma_addr[msg_id]) and the source lkey is the PD-wide local_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs layer does not constrain the transfer length to max_chunk_size. msg_id and off are bounded against queue_depth and max_chunk_size in rtrs_srv_rdma_done(), but desc[0].len is a separate field that was not checked against the chunk size. A peer that advertises desc[0].len larger than max_chunk_size can make the posted RDMA write read past the chunk's mapped region. The resulting behaviour depends on the IOMMU configuration: with no IOMMU or in passthrough mode the read may extend into memory adjacent to the chunk and be returned to the peer, which can disclose host memory; with a translating IOMMU the out-of-range access is expected to fault and abort the connection. In either case the transfer exceeds what the protocol permits and is driven by a remote peer. Reject a descriptor length above max_chunk_size, mirroring the existing off >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients do not exceed it: the client sets desc[0].len to its MR length, which is capped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE). Added Reference https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc Added Reference https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667 Added Reference https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb Added Reference https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da Added Reference https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66 Added Reference https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1 Added Reference https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f