CVE-2026-64102
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Reject MPA FPDU length underflow before signed receive math
A malicious connected siw peer can send an iWARP FPDU whose MPA length
field (chdr->mpalen, 16 bit big-endian, peer-controlled) is smaller
than the fixed DDP/RDMAP header for the announced opcode. Soft-iWARP
parses the full header in siwgethdr() based on iwarp_pktinfo[opcode]
.hdrlen, but never compares mpalen against that header length.
siwtcprx_data() then derives
srx->fpdupartrem = be16tocpu(mpalen) - fpdupart_rcvd
+ MPAHDRSIZE;
where fpdupartrcvd equals iwarppktinfo[opcode].hdrlen at this
point. For a tagged WRITE (hdrlen 16, MPAHDR_SIZE 2) the smallest
on-wire mpalen of 0 yields fpdupartrem = -14, and any mpalen below
hdrlen - MPAHDR_SIZE underflows to a negative int.
The signed value then flows into siwprocwrite()/siwprocrresp() as
bytes = min(srx->fpdupartrem, srx->skb_new);
is handed to siwcheckmem() as an int len (whose interval check
addr + len > mem->va + mem->len is satisfied for a valid base when
len is negative), and reaches siwrxdata() -> siwrxkva() /
siwrxumem() -> skbcopybits() as a signed copy length. The header
copy branch in skbcopybits() promotes that to size_t, producing a
multi-gigabyte read.
KASAN under a KUnit harness that drives the real kernel TCP receive
path -- a loopback AF_INET socketpair, the malformed FPDU written via
kernelsendmsg, skdataready firing in softirq, tcpread_sock
dispatching to siwtcprx_data -- reports:
BUG: KASAN: use-after-free in skbcopybits+0x284/0x480
Read of size 4294967295 at addr ffff888...
Call Trace:
skbcopybits
siwrxkva
siwrxdata
siwcheckmem
siwprocwrite
siwtcprx_data
_tcpread_sock
siwqpllpdataready
tcpdataready
tcpdataqueue
Add the missing invariant at the earliest point where the peer header
is fully assembled. iwarppktinfo[*].hdrlen - MPAHDRSIZE is exactly
the value the siw transmitter uses as the minimum mpa_len for each
opcode (drivers/infiniband/sw/siw/siw_qp.c:33), so this matches the
protocol contract. Out-of-range FPDUs terminate the connection with
TERMERRORLAYERLLP / LLPETYPEMPA / LLPECODEFPDUSTART -- which
is RFC 5044 Section 8 error code 3 ("Marker and ULPDU Length fields
do not agree on the start of an FPDU"), the correct framing-error
class for this inconsistency.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0ce1bc9e46ecabe84772bb561e373c0d9876d6f2, https://git.kernel.org/stable/c/1012896f4225e8f801ff3c1648023845b66dfb11, https://git.kernel.org/stable/c/14553be882d9ce91749c9d64041de66e34ad8e70, https://git.kernel.org/stable/c/33a8b5e971e294ec2a7b74211c545e09efd8e9ac, https://git.kernel.org/stable/c/4a331582011d9e8089af8aa2a61ec6b4443bb245, https://git.kernel.org/stable/c/683f7cfbf514193d63c0efa079f3352bde84c2e0, https://git.kernel.org/stable/c/775b4dc9618a99a1fa48b57554041a5dc17e1336, https://git.kernel.org/stable/c/c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64102.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64102, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git