RDMA/siw: Fix immediate work request flush to completion queue

Summary

CVECVE-2022-50736
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2025-12-24 13:16:00 UTC
Updated2026-08-04 10:18:22 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix immediate work request flush to completion queue Correctly set send queue element opcode during immediate work request flushing in post sendqueue operation, if the QP is in ERROR state. An undefined ocode value results in out-of-bounds access to an array for mapping the opcode between siw internal and RDMA core representation in work completion generation. It resulted in a KASAN BUG report of type 'global-out-of-bounds' during NFSoRDMA testing. This patch further fixes a potential case of a malicious user which may write undefined values for completion queue elements status or opcode, if the CQ is memory mapped to user land. It avoids the same out-of-bounds access to arrays for status and opcode mapping as described above.

Risk And Classification

Primary CVSS: v3.1 7.1 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

EPSS: 0.001660000 probability, percentile 0.062030000 (date 2026-08-06)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
3.1CNADECLARED7.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b 6af043089d3f1210776d19b6fdabea610d4c7699 git Not specified
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b 75af03fdf35acf15a3977f7115f6b8d10dff4bc7 git Not specified
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b f8d8fbd3b6d6cc3f25790cca5cffe8ded512fef6 git Not specified
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b 355d2eca68c10d713a42f68e62044b3d1c300471 git Not specified
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b f3d26a8589dfdeff328779b511f71fb90b10005e git Not specified
CNA Linux Linux affected 303ae1cdfdf7280ff4cfbbe65563b5ff15bb025b bdf1da5df9da680589a7f74448dd0a94dd3e1446 git Not specified
CNA Linux Linux affected 5.3 Not specified
CNA Linux Linux unaffected 5.3 semver Not specified
CNA Linux Linux unaffected 5.4.229 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.163 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.86 5.15.* semver Not specified
CNA Linux Linux unaffected 6.0.16 6.0.* semver Not specified
CNA Linux Linux unaffected 6.1.2 6.1.* semver Not specified
CNA Linux Linux unaffected 6.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f8d8fbd3b6d6cc3f25790cca5cffe8ded512fef6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/75af03fdf35acf15a3977f7115f6b8d10dff4bc7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/355d2eca68c10d713a42f68e62044b3d1c300471 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bdf1da5df9da680589a7f74448dd0a94dd3e1446 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f3d26a8589dfdeff328779b511f71fb90b10005e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6af043089d3f1210776d19b6fdabea610d4c7699 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report