7.1

CVE-2026-92525

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

For a user QP, qp->sq.queue is a ring the application writes directly,
so rxe_post_send() takes the is_user branch and only schedules send_task
without validating the WQE. rxe_requester() consumes it in place via
req_next_wqe() and calls copy_data(), which indexes
&wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge.
Only the kernel path bounds num_sge (validate_send_wr()); the user WQE
is never checked, so a local unprivileged user can post a WQE with an
out-of-range cur_sge or oversized num_sge and force an out-of-bounds
read of the per-WQE sge array in copy_data() (vmalloc OOB read, local
DoS).

Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way
get_srq_wqe() already guards SRQ entries, and bound cur_sge only when
the WQE carries payload (dma.resid): copy_data() returns early on a
zero-length copy before touching dma->sge[], so a zero-payload WQE --
the only kind a max_sge == 0 QP can post -- stays valid.

Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < 69d3ccf6543f24c452a020c8028ca6f46cb1e8db
Status affected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < 750bba6ce9bb0b11d6a166031c9728ae3f21765e
Status affected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < c067aa7b231e91a18a1b3666201ab14dfb00347a
Status affected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62
Status affected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < 5ec111ddc1f727c1e4580aea459842ae5a8359a5
Status affected
Version 8700e3e7c4857d28ebaa824509934556da0b3e76
Version < 126c757e4cd46f866ddc283143b58eb4d9bf52cd
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.8
Status affected
Version 0
Version < 4.8
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/69d3ccf6543f24c452a020c8028ca6f46cb1e8db
https://git.kernel.org/stable/c/750bba6ce9bb0b11d6a166031c9728ae3f21765e
https://git.kernel.org/stable/c/c067aa7b231e91a18a1b3666201ab14dfb00347a
https://git.kernel.org/stable/c/13cb7160e5b791f5e3ecf9311cf32849fe7e9b62
https://git.kernel.org/stable/c/5ec111ddc1f727c1e4580aea459842ae5a8359a5
https://git.kernel.org/stable/c/126c757e4cd46f866ddc283143b58eb4d9bf52cd