---
id: CVE-2026-98365
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access

  mr_check_range() validates that [iova, iova+length) falls within the
  registered MR range using…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access

  mr_check_range() validates that [iova, iova+length) falls within the
  registered MR range using…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 <
    b7d2118660545a00b21e83010ded1a231c6fb8c5
  - >-
    Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 <
    5d9426a74fc8cb8f375fcdc19b465a030f9b8cab
  - >-
    Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 <
    2f3b705144e3a3c14184fec6e354680081fe91ec
  - >-
    Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 <
    3431f525718f6b07da308cda6d44f8cb548bbd37
  - >-
    Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 <
    d10e2a08799e858d3e71ea4169bcd018f216d444
  - Linux 4.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:30.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98365'
references:
  - url: 'https://git.kernel.org/stable/c/2f3b705144e3a3c14184fec6e354680081fe91ec'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3431f525718f6b07da308cda6d44f8cb548bbd37'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5d9426a74fc8cb8f375fcdc19b465a030f9b8cab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b7d2118660545a00b21e83010ded1a231c6fb8c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d10e2a08799e858d3e71ea4169bcd018f216d444'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.393Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access

mr_check_range() validates that [iova, iova+length) falls within the
registered MR range using wraparound-prone arithmetic:

    if (iova < mr->ibmr.iova ||
        iova + length > mr->ibmr.iova + mr->ibmr.length)

A remote peer can craft an RDMA-Write/Read RETH so that iova + length
wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the
check. rxe_mr_iova_to_index() then computes a huge index (int idx, only
guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences
mr->page_info[huge], causing an out-of-bounds read/write and a kernel
oops that is triggerable by an unauthenticated remote peer.

Rewrite the check in overflow-safe form; the first two clauses guarantee
that the subsequent subtractions do not underflow:

    if (iova < mr->ibmr.iova ||
        length > mr->ibmr.length ||
        iova - mr->ibmr.iova > mr->ibmr.length - length)

With the fix, mr_check_range() returns -EINVAL for the crafted iova and
the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
