7.8
CVE-2026-74377
- EPSS 0.13%
- Veröffentlicht 15.08.2026 05:58:55
- Zuletzt bearbeitet 17.08.2026 06:19:32
- CVE-Watchlists
- Unerledigt
RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path For non-SRQ QPs, the responder reads WQE fields directly from the shared queue buffer mapped into userspace. This allows a malicious user to modify fields like num_sge or sge entries while the kernel is processing the WQE, leading to out-of-bounds reads in rxe_resp_check_length() and copy_data(). Introduce get_recv_wqe() that validates num_sge and copies the WQE to a kernel-local buffer before processing, matching the approach already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is reused since SRQ and non-SRQ paths are mutually exclusive per QP.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
2e60378fb3c8b51c94103bb40014c4fe38fa5033
Status
affected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78
Status
affected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
9fa785137303f7109c23dea779b8dedc67c9b531
Status
affected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
5420eebf3b3c162bfaf965f30e61cd1d689e5732
Status
affected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b
Status
affected
Version
8700e3e7c4857d28ebaa824509934556da0b3e76
Version <
d6ab440240a04b8737ee4c7bb21af9182e451733
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.8
Status
affected
Version
0
Version <
4.8
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.03 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/2e60378fb3c8b51c94103bb40014c4fe38fa5033
https://git.kernel.org/stable/c/fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78
https://git.kernel.org/stable/c/9fa785137303f7109c23dea779b8dedc67c9b531
https://git.kernel.org/stable/c/5420eebf3b3c162bfaf965f30e61cd1d689e5732
https://git.kernel.org/stable/c/a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b
https://git.kernel.org/stable/c/d6ab440240a04b8737ee4c7bb21af9182e451733