CVE-2026-92525

Summary

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE. rxe_requester() consumes it in place via req_next_wqe() and calls copy_data(), which indexes &wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge. Only the kernel path bounds num_sge (validate_send_wr()); the user WQE is never checked, so a local unprivileged user can post a WQE with an out-of-range cur_sge or oversized num_sge and force an out-of-bounds read of the per-WQE sge array in copy_data() (vmalloc OOB read, local DoS).

Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way get_srq_wqe() already guards SRQ entries, and bound cur_sge only when the WQE carries payload (dma.resid): copy_data() returns early on a zero-length copy before touching dma->sge[], so a zero-payload WQE – the only kind a max_sge == 0 QP can post – stays valid.

Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < 69d3ccf6543f24c452a020c8028ca6f46cb1e8dbaffected
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < 750bba6ce9bb0b11d6a166031c9728ae3f21765eaffected
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < c067aa7b231e91a18a1b3666201ab14dfb00347aaffected
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62affected
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < 5ec111ddc1f727c1e4580aea459842ae5a8359a5affected
LinuxLinux8700e3e7c4857d28ebaa824509934556da0b3e76 < 126c757e4cd46f866ddc283143b58eb4d9bf52cdaffected
LinuxLinux4.8affected
LinuxLinux0 < 4.8unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References