All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math
Date: Sun, 19 Jul 2026 17:39:24 +0200	[thread overview]
Message-ID: <2026071920-CVE-2026-64102-dcb6@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Reject MPA FPDU length underflow before signed receive math

A malicious connected siw peer can send an iWARP FPDU whose MPA length
field (c_hdr->mpa_len, 16 bit big-endian, peer-controlled) is smaller
than the fixed DDP/RDMAP header for the announced opcode. Soft-iWARP
parses the full header in siw_get_hdr() based on iwarp_pktinfo[opcode]
.hdr_len, but never compares mpa_len against that header length.

siw_tcp_rx_data() then derives

    srx->fpdu_part_rem = be16_to_cpu(mpa_len) - fpdu_part_rcvd
                         + MPA_HDR_SIZE;

where fpdu_part_rcvd equals iwarp_pktinfo[opcode].hdr_len at this
point. For a tagged WRITE (hdr_len 16, MPA_HDR_SIZE 2) the smallest
on-wire mpa_len of 0 yields fpdu_part_rem = -14, and any mpa_len below
hdr_len - MPA_HDR_SIZE underflows to a negative int.

The signed value then flows into siw_proc_write()/siw_proc_rresp() as

    bytes = min(srx->fpdu_part_rem, srx->skb_new);

is handed to siw_check_mem() as an int len (whose interval check
addr + len > mem->va + mem->len is satisfied for a valid base when
len is negative), and reaches siw_rx_data() -> siw_rx_kva() /
siw_rx_umem() -> skb_copy_bits() as a signed copy length. The header
copy branch in skb_copy_bits() promotes that to size_t, producing a
multi-gigabyte read.

KASAN under a KUnit harness that drives the real kernel TCP receive
path -- a loopback AF_INET socketpair, the malformed FPDU written via
kernel_sendmsg, sk_data_ready firing in softirq, tcp_read_sock
dispatching to siw_tcp_rx_data -- reports:

    BUG: KASAN: use-after-free in skb_copy_bits+0x284/0x480
    Read of size 4294967295 at addr ffff888...
    Call Trace:
     skb_copy_bits
     siw_rx_kva
     siw_rx_data
     siw_check_mem
     siw_proc_write
     siw_tcp_rx_data
     __tcp_read_sock
     siw_qp_llp_data_ready
     tcp_data_ready
     tcp_data_queue

Add the missing invariant at the earliest point where the peer header
is fully assembled. iwarp_pktinfo[*].hdr_len - MPA_HDR_SIZE is exactly
the value the siw transmitter uses as the minimum mpa_len for each
opcode (drivers/infiniband/sw/siw/siw_qp.c:33), so this matches the
protocol contract. Out-of-range FPDUs terminate the connection with
TERM_ERROR_LAYER_LLP / LLP_ETYPE_MPA / LLP_ECODE_FPDU_START -- which
is RFC 5044 Section 8 error code 3 ("Marker and ULPDU Length fields
do not agree on the start of an FPDU"), the correct framing-error
class for this inconsistency.

The Linux kernel CVE team has assigned CVE-2026-64102 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 5.10.258 with commit 683f7cfbf514193d63c0efa079f3352bde84c2e0
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 5.15.209 with commit 4a331582011d9e8089af8aa2a61ec6b4443bb245
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 6.1.175 with commit 33a8b5e971e294ec2a7b74211c545e09efd8e9ac
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 6.6.142 with commit 14553be882d9ce91749c9d64041de66e34ad8e70
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 6.12.92 with commit c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 6.18.34 with commit 1012896f4225e8f801ff3c1648023845b66dfb11
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 7.0.11 with commit 775b4dc9618a99a1fa48b57554041a5dc17e1336
	Issue introduced in 5.3 with commit 8b6a361b8c482f22ac99c3273285ff16b23fba91 and fixed in 7.1 with commit 0ce1bc9e46ecabe84772bb561e373c0d9876d6f2

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64102
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/infiniband/sw/siw/siw_qp_rx.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/683f7cfbf514193d63c0efa079f3352bde84c2e0
	https://git.kernel.org/stable/c/4a331582011d9e8089af8aa2a61ec6b4443bb245
	https://git.kernel.org/stable/c/33a8b5e971e294ec2a7b74211c545e09efd8e9ac
	https://git.kernel.org/stable/c/14553be882d9ce91749c9d64041de66e34ad8e70
	https://git.kernel.org/stable/c/c7c0c0f4379dedec12d24dbb9dded5d2db7fd9f2
	https://git.kernel.org/stable/c/1012896f4225e8f801ff3c1648023845b66dfb11
	https://git.kernel.org/stable/c/775b4dc9618a99a1fa48b57554041a5dc17e1336
	https://git.kernel.org/stable/c/0ce1bc9e46ecabe84772bb561e373c0d9876d6f2

                 reply	other threads:[~2026-07-19 15:43 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026071920-CVE-2026-64102-dcb6@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.