OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97413

CRITICAL · CVSS 9.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's RDMA/rtrs-srv component, where an integer underflow can occur due to improper validation of a user-supplied length value. This flaw allows a malicious RDMA client to manipulate memory access, potentially leading to out-of-bounds memory access and exploitation. Organizations utilizing Linux systems with RDMA capabilities should prioritize patching this vulnerability to mitigate the risk of unauthorized memory access and potential system compromise.

CVE
CVE-2026-97413
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len <= off. A malicious RDMA client can send usr_len > off causing an integer underflow, resulting in data_len wrapping to a huge size_t value which is then passed to the rdma_ev callback as a memory length, leading to out-of-bounds memory access. Fix by reading and validating usr_len <= off before rtrs_srv_get_ops_ids() in both process_read() and process_write(), ensuring the early return path acquires no reference and has no resource leak.