Executive brief
A vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) over TCP component could allow an attacker to cause a system crash or potentially access sensitive memory. The issue occurs when the system incorrectly calculates the amount of data being sent over the network, leading to an out-of-bounds memory access. This could result in a complete service outage or unauthorized data exposure on affected servers.
Technical details
A vulnerability in the Soft-iWARP (siw) driver within the Linux kernel RDMA subsystem stems from an incorrect byte count passed to iov_iter_bvec and tcp_sendmsg_locked in siw_tcp_sendpages. Specifically, the code used the total size of the send request instead of the size of the individual page being processed. While previously benign, recent changes in the slab allocator that disallow 'sendpage' on large kmalloc allocations triggered a fallback path that does not correctly validate the iterator count, leading to an out-of-bounds read/write. An attacker can exploit this via network-reachable RDMA operations to cause a kernel panic (DoS) or potentially achieve remote code execution. Patches have been released for various stable kernel branches including 6.6.y, 6.12.y, and 6.15.y.
Affected products
- Linux Linux Kernel 6.5 to 6.6.103, 6.12.43, 6.15.11, 6.16.2
Timeline
- 2025-07-29: disclosed: Vulnerability reported and patch authored by Pedro Falcato
- 2025-08-20: patched: Fix committed to stable kernel trees
- 2025-09-11: advisory: CVE-2025-39758 published
References
- https://git.kernel.org/stable/c/42ebc16d9d2563f1a1ce0f05b643ee68d54fabf8
- https://git.kernel.org/stable/c/5661fdd218c2799001b88c17acd19f4395e4488e
- https://git.kernel.org/stable/c/673cf582fd788af12cdacfb62a6a593083542481
- https://git.kernel.org/stable/c/c18646248fed07683d4cee8a8af933fc4fe83c0d
- https://git.kernel.org/stable/c/edf82bc8150570167a33a7d54627d66614cbf841