External risk intelligence

Linux Kernel RDMA Integer Underflow Leads to Out-of-Bounds Memory Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-97413

The vulnerability resides in the RDMA transport service (rtrs-srv) within the Linux kernel. RDMA protocols are typically deployed in high-performance computing, data centers, or storage area networks that are strictly isolated from the public internet. While technically network-reachable within these internal environments, public internet exposure of this specific protocol remains highly uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a vulnerability within the Linux kernel's RDMA transport service that could allow an attacker to gain unauthorized access to memory. The issue stems from improper validation of network-supplied data, potentially leading to significant data compromise. The main concern is confirming relevance and exposure within your specific environment.

  • Remote attackers can access sensitive memory.
  • Impacts systems using specific Linux network services.
  • Verify if these Linux services are in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network messages to a Linux system running a vulnerable version of the RDMA transport service. This service processes incoming data related to read and write operations. By manipulating the length information in these messages, an attacker can cause an integer underflow, leading to an attempt to access memory beyond allocated boundaries.

  • Network access required.
  • Triggered by crafted network messages.
  • Allows out-of-bounds memory access.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a malicious RDMA client could trigger an integer underflow by sending a crafted message. This could lead to an out-of-bounds memory access within the Linux kernel's RDMA subsystem, potentially affecting service stability and allowing unauthorized memory manipulation.

  • Kernel memory access could be compromised.
  • Malicious network messages could trigger underflow.
  • Service instability or data corruption may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's RDMA transport service is affected by an integer underflow vulnerability that could lead to out-of-bounds memory access. This issue primarily impacts infrastructure and platform teams responsible for managing RDMA deployments, as well as security teams for exposure assessment. The immediate priority is to identify all instances of the affected Linux kernel component, confirm its reachability and criticality, and assign ownership for remediation planning.

  • Identify RDMA-enabled Linux systems.
  • Verify network exposure and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux RDMA transport service affected by CVE-2026-97413?

The RDMA (Remote Direct Memory Access) transport service in the Linux kernel, specifically the rtrs-srv component, allows systems to exchange data directly between memory without involving the operating system of either system. It is commonly used in high-performance computing, data centers, and storage area networks to enable extremely fast data transfers with minimal processing delay.

How does an integer underflow cause a vulnerability in this component?

The vulnerability involves a mathematical error when processing network messages. The system fails to verify that the provided data length is smaller than the available offset. When a malicious client sends a value that triggers an underflow, the internal length calculation wraps around to a massive number. The system then attempts to read or write memory based on this incorrect, extremely large size, leading to out-of-bounds memory access.

Does any network message trigger this RDMA memory issue?

No. The flaw is specifically triggered by a maliciously crafted message where the user-supplied length field exceeds the expected data offset. Standard, valid network traffic that adheres to expected length parameters does not trigger this integer underflow condition.

Is my system at risk from the internet according to Halo Surface Signal?

Halo Surface Signal labels this as unlikely for public internet exposure. Because RDMA protocols are designed for high-performance clusters or storage networks, they are almost always kept within strictly isolated internal environments. While the flaw is network-reachable, the service is rarely, if ever, exposed directly to the public internet.

What are the first steps to manage CVE-2026-97413?

Begin by inventorying your infrastructure to identify which Linux systems have the RDMA transport service enabled. Once identified, evaluate whether these systems reside within restricted, internal networks as expected. Work with your platform or infrastructure teams to confirm the necessity of the service and prioritize updates for systems that support critical business operations.

References