External risk intelligence

Linux Kernel RDMA/srpt Incorrect Counter Update Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-100075

The vulnerability exists within the Linux kernel RDMA/srpt (SCSI RDMA Protocol) target component. RDMA protocols are typically deployed in high-performance, private, or isolated data center fabric environments rather than exposed directly to the public internet. While network-reachable in specialized deployments, broad public internet exposure is uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A recent vulnerability has been addressed in the Linux kernel's RDMA/srpt component. This issue could potentially impact system stability or data integrity if certain error conditions occur during operation. While the direct business impact may be limited to specific high-performance networking environments, understanding its existence is prudent.

  • Kernel code has a flaw related to managing network connections.
  • This issue could affect specific high-performance networking.
  • Confirm relevance and potential exposure within your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by triggering a specific error condition within the RDMA/srpt component of the Linux kernel. This error occurs during the allocation of context structures when a multi-buffer indirect descriptor operation fails. If not properly handled, this can lead to incorrect accounting of send queue credits, potentially impacting system stability and security.

  • Entry condition: Network exposure of the RDMA/srpt component.
  • Trigger point: Allocation failure in multi-buffer indirect descriptor operations.
  • Resulting risk: Incorrect credit accounting, system instability.

Live Threat

Current exploitation, exposure, and threat context

When RDMA communication fails, the system could incorrectly track available network credits. This might impact the stability and reliability of RDMA-enabled services.

  • RDMA context and credit accounting data at risk.
  • Exposure may occur during partial allocation failures.
  • Service instability or unreliability could result.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Linux kernel's RDMA/srpt component, potentially affecting infrastructure or platform teams responsible for high-performance networking. The first step is to identify where RDMA is deployed, assess its business criticality and reachability, and then determine the accountable owner for remediation planning.

  • Infrastructure or platform teams own the issue.
  • Verify RDMA deployment and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel RDMA/srpt component?

It is a subsystem within the Linux kernel that implements the SCSI RDMA Protocol. This technology allows high-speed data transfer between computer memory across a network, primarily used in specialized data center fabrics where performance is critical.

What is the weakness behind CVE-2026-100075?

This is an improper resource cleanup or management issue. Specifically, the kernel fails to reset internal counters correctly when an allocation error occurs during certain RDMA operations, leaving behind stale data that corrupts future network credit calculations.

How does the trigger for this vulnerability work?

An attacker must trigger a partial allocation failure during a multi-buffer indirect descriptor operation. Normal, successful RDMA operations do not trigger this error, as the bug only occurs during the failure-handling path where the kernel cleans up.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal labels this risk as Unlikely. Because RDMA/srpt is typically deployed in private, isolated data center fabrics rather than directly on the public internet, widespread internet-facing exposure is uncommon for this technology.

What are the first steps to address this vulnerability?

Infrastructure teams should first inventory systems utilizing RDMA/srpt to understand their deployment scope. Once identified, evaluate the criticality of those services and coordinate with platform owners to plan for kernel updates as part of the routine maintenance cycle.

References