CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081504-CVE-2026-74377-9467@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path For non-SRQ QPs, the responder reads WQE fields directly from the shared queue buffer mapped into userspace. This allows a malicious user to modify fields like num_sge or sge entries while the kernel is processing the WQE, leading to out-of-bounds reads in rxe_resp_check_length() and copy_data(). Introduce get_recv_wqe() that validates num_sge and copies the WQE to a kernel-local buffer before processing, matching the approach already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is reused since SRQ and non-SRQ paths are mutually exclusive per QP. The Linux kernel CVE team has assigned CVE-2026-74377 to this issue. Affected and fixed versions =========================== Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 6.1.178 with commit 2e60378fb3c8b51c94103bb40014c4fe38fa5033 Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 6.6.145 with commit fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78 Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 6.12.97 with commit 9fa785137303f7109c23dea779b8dedc67c9b531 Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 6.18.40 with commit 5420eebf3b3c162bfaf965f30e61cd1d689e5732 Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 7.1.5 with commit a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b Issue introduced in 4.8 with commit 8700e3e7c4857d28ebaa824509934556da0b3e76 and fixed in 7.2-rc1 with commit d6ab440240a04b8737ee4c7bb21af9182e451733 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74377 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/infiniband/sw/rxe/rxe_resp.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2e60378fb3c8b51c94103bb40014c4fe38fa5033 https://git.kernel.org/stable/c/fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78 https://git.kernel.org/stable/c/9fa785137303f7109c23dea779b8dedc67c9b531 https://git.kernel.org/stable/c/5420eebf3b3c162bfaf965f30e61cd1d689e5732 https://git.kernel.org/stable/c/a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b https://git.kernel.org/stable/c/d6ab440240a04b8737ee4c7bb21af9182e451733