Review reviewCritical

CVE-2026-64268

Linux

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accumulates wqe->processed, but it never checks the running total against the sink buffer length on continuation segments. siw_check_sge() resolves and validates the sink memory only on the first fragment (the if (!*mem) branch), and siw_rresp_check_ntoh() compares the cumulative length against wqe->bytes only on the final...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then accumulates wqe->processed, but it never checks the running total against the sink buffer length on continuation segments. siw_check_sge() resolves and validates the sink memory only on the first fragment (the if (!*mem) branch), and siw_rresp_check_ntoh() compares the cumulative length against wqe->bytes only on the final...

Affected product and versions

Product
Linux
Affected versions
>= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < a31b6d18ded3cc32d9ee85a6ff0726d4274887b2, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 595e6537ad1a210da32cbb9a7f91aa73090915ba, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < b2e26c955f8dd7e8d3f16c858db05245ea4fa817, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 6bc89f34a4597f9f6d41f7a60c67a3153bfe8851, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 423a78ff7928c2601013f73ec6d896f5597d0df5, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 75c93cd3c421890f49ea93f0b978b9b7bb10e5e3, >= 8b6a361b8c482f22ac99c3273285ff16b23fba91 < 7d29f7e9dbd844cae4d3e559cf78324b9642fd6b, >= 5.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available