External risk intelligence

Linux Kernel RDMA/siw Header Copy Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-98323

This vulnerability affects the Linux kernel RDMA/siw (Software iWARP) driver. While RDMA is typically used in high-performance internal data center or cluster fabrics, it is not inherently designed for direct exposure to the public internet. However, because it operates at the network stack level, it is plausibly reachable in complex, misconfigured, or uniquely deployed environments.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's RDMA/siw component could allow an attacker to overwrite critical system memory, potentially leading to a system crash or unauthorized code execution. This issue arises from how fragmented header data is handled, causing memory corruption when processing network traffic.

  • Bug in Linux kernel's network handling.
  • Critical vulnerability could impact system stability.
  • Confirm relevance and exposure for Linux systems.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by sending specially crafted network traffic to a system running a vulnerable version of the Linux kernel. The issue lies within the RDMA/siw component, where incorrect handling of fragmented headers during network reception can lead to a buffer overflow. This overflow allows an attacker to overwrite critical data, potentially leading to arbitrary code execution or denial of service.

  • No authentication or special access needed.
  • Triggered by network traffic reception.
  • Allows arbitrary code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

The Linux kernel's RDMA/siw driver could be susceptible to an out-of-bounds write when processing fragmented headers. This could occur when a header is split across multiple TCP callbacks, and the system incorrectly calculates the remaining data to be copied, potentially corrupting internal receive state.

  • Kernel receive state could be corrupted.
  • Malformed headers across TCP callbacks.
  • Uncontrolled write, affecting system stability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's RDMA/siw component is affected, implicating infrastructure and platform teams responsible for the kernel and its networking stack. The first practical move is to identify all systems running this kernel component, assess their reachability and criticality, and confirm the accountable owner for remediation.

  • Infrastructure and platform teams own this.
  • Verify Linux kernel and RDMA/siw usage.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel RDMA/siw component?

RDMA/siw, or Software iWARP, is a Linux kernel driver that enables Remote Direct Memory Access over standard TCP/IP networks. It allows systems to move data directly between the memory of two computers without involving either operating system's CPU, which is highly efficient for high-performance clusters and data center storage fabrics.

What does this CVE-2026-98323 vulnerability mean?

This is an out-of-bounds write vulnerability. It occurs because the software miscalculates the space remaining when receiving fragmented network data. This error allows incoming information to overwrite memory areas reserved for the system's internal state, which can disrupt stability or potentially allow an attacker to gain unauthorized control over the system's execution.

How is this vulnerability triggered?

The flaw is triggered when the system receives a fragmented network header split across multiple TCP callbacks. If the software incorrectly calculates the remaining length for subsequent data segments, it writes data beyond the intended buffer. It is not triggered by normal, properly formatted traffic or by connections that do not involve fragmented RDMA header reception.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal notes that while RDMA is typically used within internal, high-performance fabrics not meant for the public internet, the driver operates at the network stack level. This means it could be reachable if your infrastructure is misconfigured, uniquely deployed, or if the service is accidentally exposed to untrusted network segments.

What is the first step to address CVE-2026-98323?

You should begin by identifying which systems in your environment are actively using the RDMA/siw driver. Once located, verify the kernel version running on those assets and consult your Linux distribution provider or internal platform team to confirm if the specific patched version is available and scheduled for deployment.

References