{
  "id": "CVE-2026-98365",
  "url": "https://spydr.io/cve/CVE-2026-98365",
  "published": "2026-10-06T09:18:30.677Z",
  "modified": "2026-10-06T09:18:30.677Z",
  "score": null,
  "severity": null,
  "cvss_version": null,
  "vector": null,
  "score_source": null,
  "epss": 0.00165,
  "epss_percentile": 0.05126,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": null,
  "vendors": [
    "Linux"
  ],
  "products": [
    "Linux"
  ],
  "cwes": [],
  "description": "In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access mr_check_range() validates that [iova, iova+length) falls within the registered MR range using wraparound-prone arithmetic: if (iova < mr->ibmr.iova || iova + length > mr->ibmr.iova + mr->ibmr.length) A remote peer can craft an RDMA-Write/Read RETH so that iova + length wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the check. rxe_mr_iova_to_index() then computes a huge index (int idx, only guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences mr->page_info[huge], causing an out-of-bounds read/write and a kernel oops that is triggerable by an unauthenticated remote peer. Rewrite the check in overflow-safe form; the first two clauses guarantee that the subsequent subtractions do not underflow: if (iova < mr->ibmr.iova || length > mr->ibmr.length || iova - mr->ibmr.iova > mr->ibmr.length - length) With the fix, mr_check_range() returns -EINVAL for the crafted iova and the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.",
  "status": "Received",
  "score_type": null,
  "scores": {
    "cvss_v40": null,
    "cvss_v31": null,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2f3b705144e3a3c14184fec6e354680081fe91ec",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/3431f525718f6b07da308cda6d44f8cb548bbd37",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/5d9426a74fc8cb8f375fcdc19b465a030f9b8cab",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/b7d2118660545a00b21e83010ded1a231c6fb8c5",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/d10e2a08799e858d3e71ea4169bcd018f216d444",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98365",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
