-

CVE-2026-74346

RDMA/irdma: Fix OOB read during CQ MR registration

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Fix OOB read during CQ MR registration

Sashiko pointed out an unrelated bug during a previous patch:
https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com

This change fixes the bug by eliminating the cqmr->split field which
was not being set properly and instead just checks the CQ resize
feature flag directly.

The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE
is set, but it was not being set until CQ creation time, which is _after_
CQ memory registration (the only other place where it is referenced).

As a result, it would always be false during MR registration and would
therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2
HW and beyond:

    cqmr->shadow = (dma_addr_t)arr[req->cq_pages];

The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal
to iwmr->page_cnt and therefore equal to the size of arr, which would cause
an OOB read by one.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < a80b3b13786e9ab1c52b31a1f16c7d6708fa9220
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < 3159c6fac43dc24b34d31971884d98a7a1bf4c4b
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < ad360a31092a870633ec255b96f50181628b4de0
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < d566002de555b18cc395012c5c1cb8682fc6d2a9
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < 54cab78df0375196aaec4e3109191653d21751df
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < d5aa82da8f65562da996d184686db9d0ea718b91
Status affected
Version b48c24c2d710cf34810c555dcef883a3d35a9c08
Version < 4385ddd654d90245eeb83b3cb539670ab5c85ba4
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.14
Status affected
Version 0
Version < 5.14
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a80b3b13786e9ab1c52b31a1f16c7d6708fa9220
https://git.kernel.org/stable/c/3159c6fac43dc24b34d31971884d98a7a1bf4c4b
https://git.kernel.org/stable/c/ad360a31092a870633ec255b96f50181628b4de0
https://git.kernel.org/stable/c/d566002de555b18cc395012c5c1cb8682fc6d2a9
https://git.kernel.org/stable/c/54cab78df0375196aaec4e3109191653d21751df
https://git.kernel.org/stable/c/d5aa82da8f65562da996d184686db9d0ea718b91
https://git.kernel.org/stable/c/4385ddd654d90245eeb83b3cb539670ab5c85ba4