CVE-2026-98323 (GCVE-0-2026-98323)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:46 – Updated: 2026-10-07 06:50
VLAI
Title
RDMA/siw: Bound fragmented header copies by the remaining length
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Bound fragmented header copies by the remaining length siw_get_hdr() can receive an extended DDP/RDMAP header across more than one TCP callback. The first callback may receive most of the header, while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead of the number of missing bytes. This makes the destination move past the end of the header and overwrite the receive state, including fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd value as a copy offset, which creates an OOB write. Use the number of header bytes already received when calculating the next copy length.
Impacted products
Vendor Product Version
Linux Linux Affected: e3917c85f41ef1df64e27dc0e46ab0d803c5e73e , < 2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7 (git)
Affected: 308cd50f174c95a507527037f4de1a0396aa4325 , < af9f5b474a260ad23ffb9793d716a5e3bbce3b48 (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < 262dcd809723723ed8a4e05437ec7e9c21a8f17e (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < eb4d7a946970469b3ab0c762432bf161d5b0836c (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < 8628f8ebf41669302513fb3f0bf0eba38b226742 (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < b72dcfb9bf1f0f0147cda03dc59e4002a315067f (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d (git)
Affected: 754209850df8367c954ac1de7671c7430b1f342c , < 9ff797e516dbc1ecb73701ec4c24055712d44411 (git)
Affected: e09caa38e10bcf027100cc22b0e3cc745a39ef0a (git)
Affected: 0c14f795a9eab9344230f9933798b8ee496f497d (git)
Affected: 7fada7c6962219b6fc4ff4e62e46a936af110dd9 (git)
Affected: 5.10.150 , < 5.10.271 (semver)
Affected: 5.15.75 , < 5.15.222 (semver)
Affected: 5.4.220 , < 5.5 (semver)
Affected: 5.19.17 , < 5.20 (semver)
Affected: 6.0.3 , < 6.1 (semver)
Create a notification for this product.
Linux Linux Affected: 6.1
Unaffected: 0 , < 6.1 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_qp_rx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7",
              "status": "affected",
              "version": "e3917c85f41ef1df64e27dc0e46ab0d803c5e73e",
              "versionType": "git"
            },
            {
              "lessThan": "af9f5b474a260ad23ffb9793d716a5e3bbce3b48",
              "status": "affected",
              "version": "308cd50f174c95a507527037f4de1a0396aa4325",
              "versionType": "git"
            },
            {
              "lessThan": "262dcd809723723ed8a4e05437ec7e9c21a8f17e",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "lessThan": "eb4d7a946970469b3ab0c762432bf161d5b0836c",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "lessThan": "8628f8ebf41669302513fb3f0bf0eba38b226742",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "lessThan": "b72dcfb9bf1f0f0147cda03dc59e4002a315067f",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "lessThan": "e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "lessThan": "9ff797e516dbc1ecb73701ec4c24055712d44411",
              "status": "affected",
              "version": "754209850df8367c954ac1de7671c7430b1f342c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e09caa38e10bcf027100cc22b0e3cc745a39ef0a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0c14f795a9eab9344230f9933798b8ee496f497d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7fada7c6962219b6fc4ff4e62e46a936af110dd9",
              "versionType": "git"
            },
            {
              "lessThan": "5.10.271",
              "status": "affected",
              "version": "5.10.150",
              "versionType": "semver"
            },
            {
              "lessThan": "5.15.222",
              "status": "affected",
              "version": "5.15.75",
              "versionType": "semver"
            },
            {
              "lessThan": "5.5",
              "status": "affected",
              "version": "5.4.220",
              "versionType": "semver"
            },
            {
              "lessThan": "5.20",
              "status": "affected",
              "version": "5.19.17",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1",
              "status": "affected",
              "version": "6.0.3",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/siw/siw_qp_rx.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "lessThan": "6.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "5.10.150",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "5.15.75",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "6.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.4.220",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.19.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.0.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Bound fragmented header copies by the remaining length\n\nsiw_get_hdr() can receive an extended DDP/RDMAP header across more than\none TCP callback. The first callback may receive most of the header,\nwhile the next one still limits the copy to hdrlen - MIN_DDP_HDR instead\nof the number of missing bytes. This makes the destination move past the\nend of the header and overwrite the receive state, including\nfpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd\nvalue as a copy offset, which creates an OOB write.\n\nUse the number of header bytes already received when calculating the\nnext copy length."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The malformed input is the remote iWARP peer\u0027s own MPA/DDP/RDMAP header bytes on the siw TCP connection. The peer splits an extended header (e.g. RDMA Read Request, 44 bytes) across TCP segments, and siw_qp_llp_data_ready() -\u003e tcp_read_sock() -\u003e siw_tcp_rx_data() -\u003e siw_get_hdr() parses them. The transport is routable TCP.\nAC:L - The peer fully controls TCP segmentation, so it can deterministically end a segment with fpdu_part_rcvd between 16 and hdrlen. The next segment then copies hdrlen-16 bytes at that offset. No race or state outside the attacker\u0027s control is involved beyond siw serving an iWARP listener.\nPR:N - Once the MPA exchange puts the QP in RTS, siw_get_hdr() parses every incoming FPDU header, and neither MPA nor DDP authenticates the peer. ULP authorisation (such as an nvmet-rdma host NQN check) only arrives in messages parsed by this same path, so the overflow fires before any credential check.\nUI:N - No victim action is needed. The attacker connects to the iWARP service and sends crafted fragmented FPDUs, and siw processes them in its sk_data_ready callback.\nS:U - The corruption is confined to kernel memory of the host running siw (struct siw_qp and its neighbours). That is the same security authority as the vulnerable component, with no VM or IOMMU boundary crossed.\nC:H - The overflow writes peer bytes over siw_rx_stream fields after hdr, including fpdu_part_rcvd. A negative fpdu_part_rcvd then makes skb_copy_bits() write to c_hdr plus an attacker-chosen offset. A controlled kernel write like this can be turned into arbitrary kernel memory disclosure.\nI:H - siw_get_hdr() copies up to hdrlen-17 attacker bytes past srx-\u003ehdr (27 for rreq), overwriting the receive state. The next callback uses the corrupted negative fpdu_part_rcvd as the destination offset of skb_copy_bits(), giving an out-of-bounds kernel write whose offset and data are attacker-controlled.\nA:H - Corrupting fpdu_part_rcvd/fpdu_part_rem and writing out of bounds from siw_qp crashes or panics the kernel. A remote peer can repeat this on every connection."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:50:03.019Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7"
        },
        {
          "url": "https://git.kernel.org/stable/c/af9f5b474a260ad23ffb9793d716a5e3bbce3b48"
        },
        {
          "url": "https://git.kernel.org/stable/c/262dcd809723723ed8a4e05437ec7e9c21a8f17e"
        },
        {
          "url": "https://git.kernel.org/stable/c/eb4d7a946970469b3ab0c762432bf161d5b0836c"
        },
        {
          "url": "https://git.kernel.org/stable/c/8628f8ebf41669302513fb3f0bf0eba38b226742"
        },
        {
          "url": "https://git.kernel.org/stable/c/b72dcfb9bf1f0f0147cda03dc59e4002a315067f"
        },
        {
          "url": "https://git.kernel.org/stable/c/e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d"
        },
        {
          "url": "https://git.kernel.org/stable/c/9ff797e516dbc1ecb73701ec4c24055712d44411"
        }
      ],
      "title": "RDMA/siw: Bound fragmented header copies by the remaining length",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98323",
    "datePublished": "2026-10-06T08:46:17.150Z",
    "dateReserved": "2026-09-25T10:25:14.340Z",
    "dateUpdated": "2026-10-07T06:50:03.019Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98323",
      "date": "2026-10-08",
      "epss": "0.00559",
      "percentile": "0.44785"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/infiniband/sw/siw/siw_qp_rx.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7",
                    "status": "affected",
                    "version": "e3917c85f41ef1df64e27dc0e46ab0d803c5e73e",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "af9f5b474a260ad23ffb9793d716a5e3bbce3b48",
                    "status": "affected",
                    "version": "308cd50f174c95a507527037f4de1a0396aa4325",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "262dcd809723723ed8a4e05437ec7e9c21a8f17e",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eb4d7a946970469b3ab0c762432bf161d5b0836c",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8628f8ebf41669302513fb3f0bf0eba38b226742",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b72dcfb9bf1f0f0147cda03dc59e4002a315067f",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "9ff797e516dbc1ecb73701ec4c24055712d44411",
                    "status": "affected",
                    "version": "754209850df8367c954ac1de7671c7430b1f342c",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "e09caa38e10bcf027100cc22b0e3cc745a39ef0a",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "0c14f795a9eab9344230f9933798b8ee496f497d",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "7fada7c6962219b6fc4ff4e62e46a936af110dd9",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5.10.271",
                    "status": "affected",
                    "version": "5.10.150",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.15.222",
                    "status": "affected",
                    "version": "5.15.75",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.5",
                    "status": "affected",
                    "version": "5.4.220",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.20",
                    "status": "affected",
                    "version": "5.19.17",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.1",
                    "status": "affected",
                    "version": "6.0.3",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/infiniband/sw/siw/siw_qp_rx.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "lessThan": "6.1",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Bound fragmented header copies by the remaining length\n\nsiw_get_hdr() can receive an extended DDP/RDMAP header across more than\none TCP callback. The first callback may receive most of the header,\nwhile the next one still limits the copy to hdrlen - MIN_DDP_HDR instead\nof the number of missing bytes. This makes the destination move past the\nend of the header and overwrite the receive state, including\nfpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd\nvalue as a copy offset, which creates an OOB write.\n\nUse the number of header bytes already received when calculating the\nnext copy length."
          }
        ],
        "id": "CVE-2026-98323",
        "lastModified": "2026-10-07T07:17:08.990",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 3.9,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:24.403",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/262dcd809723723ed8a4e05437ec7e9c21a8f17e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/2c6fbcf4bfac0b2b186acc8d91154c0fa24468a7"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/8628f8ebf41669302513fb3f0bf0eba38b226742"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/9ff797e516dbc1ecb73701ec4c24055712d44411"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/af9f5b474a260ad23ffb9793d716a5e3bbce3b48"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b72dcfb9bf1f0f0147cda03dc59e4002a315067f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e6bdfdf3bcb02d0d626a45e8c98b7e63d2fddf9d"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/eb4d7a946970469b3ab0c762432bf161d5b0836c"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "important",
      "current_release_date": "2026-10-08T16:47:36Z",
      "cve": "CVE-2026-98323",
      "id": "CVE-2026-98323",
      "initial_release_date": "2026-10-08T16:47:36Z",
      "product_status:known_affected": "230",
      "product_status:known_not_affected": "117",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98323",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98323.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…