External risk intelligence

Linux Kernel RDMA Integer Overflow Leads to Out-of-Bounds Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-98365

The vulnerability affects the Linux kernel RDMA (Remote Direct Memory Access) over Converged Ethernet (RoCE) implementation. While RDMA is network-reachable, it is typically restricted to high-performance computing, data center fabrics, or specialized back-end storage networks rather than exposed directly to the public internet, making wide-scale public exposure uncommon.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's RDMA component could allow unauthenticated remote attackers to cause a kernel crash through an out-of-bounds read or write. This issue stems from an integer overflow in how memory ranges are checked, potentially leading to system instability.

  • Unauthenticated remote attackers can crash the system.
  • Matters due to potential system instability and disruption.
  • Confirm if RDMA over Converged Ethernet is in use.

Attack Path

How an attacker could exploit the issue

An attacker can initiate contact with a vulnerable system over the network, requiring no prior authentication. By sending a specially crafted RDMA request, they can trick the system into performing an out-of-bounds read or write operation within the kernel. This vulnerability can lead to a kernel crash or potentially allow an attacker to gain control of the system.

  • Network access required.
  • Malicious RDMA request triggers vulnerability.
  • Kernel crash or control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to cause a kernel out-of-bounds read or write. This occurs when a crafted RDMA operation triggers an integer overflow in the Linux kernel's RDMA/rxe component, leading to a denial-of-service condition.

  • Kernel memory integrity.
  • Crafted RDMA packets bypass checks.
  • Denial-of-service or kernel crash.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's RDMA/rxe component requires immediate attention from teams managing Linux infrastructure and potentially network configurations. The first step is to identify all systems running the affected Linux kernel, determine if RDMA/rxe is enabled and exposed externally, and confirm which systems are business-critical. Once these systems are identified, the accountable owner should be engaged to plan for remediation, prioritizing systems with greater exposure or criticality.

  • Infrastructure teams own the issue.
  • Verify RDMA/rxe exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux RDMA/rxe component?

The RDMA/rxe component is the software implementation of Remote Direct Memory Access over Converged Ethernet (RoCE) within the Linux kernel. It allows computers in a network to access each other's memory directly without involving the operating system of either machine, which significantly increases data transfer speeds. This technology is commonly used in data centers, high-performance computing clusters, and specialized storage networks to minimize latency during heavy data exchange.

How does an integer overflow cause this vulnerability?

This vulnerability is caused by an integer overflow in the memory range validation logic. When the kernel checks if a requested memory access is valid, it performs arithmetic on the memory address and length. By sending a specifically crafted request, an attacker forces these numbers to wrap around, creating a value that bypasses safety checks. This allows the system to attempt an out-of-bounds memory operation, which can lead to a kernel crash.

Do I need to be authenticated to trigger CVE-2026-98365?

No. The vulnerability is triggerable by an unauthenticated remote peer. The attacker does not need to have existing user access or login credentials on the target system. Simply being able to send a specially crafted RDMA network packet to the vulnerable software is sufficient to initiate the incorrect memory operation. Standard, legitimate RDMA operations that fall within valid memory boundaries will not trigger this bug.

Is my system at risk if it is not internet-facing?

Halo Surface Signal indicates that while this vulnerability is network-reachable, RoCE is typically confined to back-end, high-performance fabrics or data center environments rather than the public internet. Consequently, direct public exposure is uncommon. However, if your internal network allows reachability between untrusted systems and machines running the affected Linux kernel with RDMA/rxe enabled, those internal systems are still at risk.

When should I take action for this Linux kernel issue?

You should prioritize taking action if your environment relies on Linux infrastructure where RDMA/rxe is active. Start by auditing your inventory to locate systems running the vulnerable kernel and confirm where RDMA services are enabled. Assess the criticality of these machines to your operations. Once identified, coordinate with your infrastructure team to schedule appropriate updates or configuration changes, prioritizing the most critical or accessible systems first.

References