-
CVE-2026-74346
- EPSS 0.17%
- Veröffentlicht 15.08.2026 05:58:34
- Zuletzt bearbeitet 17.08.2026 06:19:29
- CVE-Watchlists
- Unerledigt
RDMA/irdma: Fix OOB read during CQ MR registration
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix OOB read during CQ MR registration
Sashiko pointed out an unrelated bug during a previous patch:
https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com
This change fixes the bug by eliminating the cqmr->split field which
was not being set properly and instead just checks the CQ resize
feature flag directly.
The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE
is set, but it was not being set until CQ creation time, which is _after_
CQ memory registration (the only other place where it is referenced).
As a result, it would always be false during MR registration and would
therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2
HW and beyond:
cqmr->shadow = (dma_addr_t)arr[req->cq_pages];
The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal
to iwmr->page_cnt and therefore equal to the size of arr, which would cause
an OOB read by one.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
a80b3b13786e9ab1c52b31a1f16c7d6708fa9220
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
3159c6fac43dc24b34d31971884d98a7a1bf4c4b
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
ad360a31092a870633ec255b96f50181628b4de0
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
d566002de555b18cc395012c5c1cb8682fc6d2a9
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
54cab78df0375196aaec4e3109191653d21751df
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
d5aa82da8f65562da996d184686db9d0ea718b91
Status
affected
Version
b48c24c2d710cf34810c555dcef883a3d35a9c08
Version <
4385ddd654d90245eeb83b3cb539670ab5c85ba4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.14
Status
affected
Version
0
Version <
5.14
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.069 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a80b3b13786e9ab1c52b31a1f16c7d6708fa9220
https://git.kernel.org/stable/c/3159c6fac43dc24b34d31971884d98a7a1bf4c4b
https://git.kernel.org/stable/c/ad360a31092a870633ec255b96f50181628b4de0
https://git.kernel.org/stable/c/d566002de555b18cc395012c5c1cb8682fc6d2a9
https://git.kernel.org/stable/c/54cab78df0375196aaec4e3109191653d21751df
https://git.kernel.org/stable/c/d5aa82da8f65562da996d184686db9d0ea718b91
https://git.kernel.org/stable/c/4385ddd654d90245eeb83b3cb539670ab5c85ba4