CVE-2026-74394
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
RDMA/srpt: fix integer overflow in immediate data length check
imm_buf->len is a user-controlled uint32_t received from the network. Adding it to imm_data_offset without overflow checking allows a malicious initiator to send len=0xFFFFFFFF, causing req_size to wrap around to a small value, bypassing the bounds check, and subsequently passing a ~4GB length to sg_init_one().
Use check_add_overflow() to detect wrapping before the comparison.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < 3efa5301137140a3ca3677a9098c0a93a0acfd49 | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < 067b9556eeb007f28b7c2033b4dcde5b6d88418f | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < dcf7a986f377cce0749ed53f1d64195fbd5fdf91 | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < 07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < 65572fbd86033ae2370125593d59b8be34253aaf | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < 72497172a4799119a0282a5eb5e2b8ddcc821921 | affected |
| Linux | Linux | 5dabcd0456d7ee17c2c7a17d7c2305444d2b9639 < eb4ecdf631fe00e8020bf461503cb9b7017ed796 | affected |
| Linux | Linux | 5.0 | affected |
| Linux | Linux | 0 < 5.0 | unaffected |
| Linux | Linux | 5.10.261 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.212 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.97 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d
- https://git.kernel.org/stable/c/3efa5301137140a3ca3677a9098c0a93a0acfd49
- https://git.kernel.org/stable/c/067b9556eeb007f28b7c2033b4dcde5b6d88418f
- https://git.kernel.org/stable/c/dcf7a986f377cce0749ed53f1d64195fbd5fdf91
- https://git.kernel.org/stable/c/07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e
- https://git.kernel.org/stable/c/65572fbd86033ae2370125593d59b8be34253aaf
- https://git.kernel.org/stable/c/72497172a4799119a0282a5eb5e2b8ddcc821921
- https://git.kernel.org/stable/c/eb4ecdf631fe00e8020bf461503cb9b7017ed796
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.