CVE-2026-64269
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdmawritesg
When the server answers an RTRS READ, rdmawritesg() builds the source
scatter/gather entry for the IBWRRDMA_WRITE that returns data to the
peer. Its length is taken directly from the wire descriptor:
plist->length = le32tocpu(id->rd_msg->desc[0].len);
rd_msg points into the chunk buffer that the remote peer filled via
RDMA-WRITE-WITH-IMM (rtrssrvrdmadone() -> processio_req() ->
process_read()), so desc[0].len is attacker-controlled and, before this
change, was only rejected when zero. The source address is the fixed
chunk start (dmaaddr[msgid]) and the source lkey is the PD-wide
localdmalkey, which is not tied to the chunk's MR mapping, so the verbs
layer does not constrain the transfer length to maxchunksize. msg_id
and off are bounded against queuedepth and maxchunk_size in
rtrssrvrdma_done(), but desc[0].len is a separate field that was not
checked against the chunk size.
A peer that advertises desc[0].len larger than maxchunksize can make
the posted RDMA write read past the chunk's mapped region. The resulting
behaviour depends on the IOMMU configuration: with no IOMMU or in
passthrough mode the read may extend into memory adjacent to the chunk
and be returned to the peer, which can disclose host memory; with a
translating IOMMU the out-of-range access is expected to fault and abort
the connection. In either case the transfer exceeds what the protocol
permits and is driven by a remote peer.
Reject a descriptor length above maxchunksize, mirroring the existing
off >= maxchunksize bound in rtrssrvrdma_done(). Legitimate clients
do not exceed it: the client sets desc[0].len to its MR length, which is
capped at the negotiated maxiosize (maxchunksize - MAXHDRSIZE).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc, https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667, https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb, https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da, https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66, https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1, https://git.kernel.org/stable/c/a35b7a8728a53ddc80b323970689fa5985816836, https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64269.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64269, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git