Executive brief
The Linux kernel's RDMA/srp (SCSI RDMA Protocol) driver fails to validate the length of incoming credential and asynchronous event requests. A malicious storage target can send truncated messages that cause the driver to read uninitialized heap memory beyond the receive buffer boundary, potentially exposing sensitive kernel data. This information leakage could aid in bypassing kernel address space layout randomization (ASLR) defenses.
Technical details
This is an information disclosure vulnerability in the RDMA/srp driver's request handling. The vulnerability occurs in srp_process_cred_req() and srp_process_aer_req() functions, which read fixed-size fields (tag, lun) from received SRP_CRED_REQ and SRP_AER_REQ messages without verifying that the complete message was received. When max_ti_iu_len (advertised by the target during login) is small (e.g., 8 bytes), the kernel allocates a kmalloc-8 slab object, but then reads beyond this boundary. The leaked bytes are included in SRP_CRED_RSP responses sent back to the target. Similarly, srp_process_rsp() reads rsp->data[3] without checking resp_data_len. The attack requires a malicious RDMA target that advertises a small max_ti_iu_len and sends truncated requests. The fix validates the message length before reading these fields and drops requests shorter than expected.
Affected products
- Linux Linux kernel unspecified (RDMA/srp component)
Timeline
- 2026-09-17: disclosed
- other: Vulnerability resolved in kernel commit addressing srp_recv_done() validation