RDMA/irdma: Fix OOB read during CQ MR registration
Summary
| CVE | CVE-2026-74346 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:35 UTC |
| Updated | 2026-08-17 06:19:29 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix OOB read during CQ MR registration Sashiko pointed out an unrelated bug during a previous patch: https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com This change fixes the bug by eliminating the cqmr->split field which was not being set properly and instead just checks the CQ resize feature flag directly. The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE is set, but it was not being set until CQ creation time, which is _after_ CQ memory registration (the only other place where it is referenced). As a result, it would always be false during MR registration and would therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2 HW and beyond: cqmr->shadow = (dma_addr_t)arr[req->cq_pages]; The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal to iwmr->page_cnt and therefore equal to the size of arr, which would cause an OOB read by one. |
Risk And Classification
EPSS: 0.001720000 probability, percentile 0.069690000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 a80b3b13786e9ab1c52b31a1f16c7d6708fa9220 git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 3159c6fac43dc24b34d31971884d98a7a1bf4c4b git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 ad360a31092a870633ec255b96f50181628b4de0 git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 d566002de555b18cc395012c5c1cb8682fc6d2a9 git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 54cab78df0375196aaec4e3109191653d21751df git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 d5aa82da8f65562da996d184686db9d0ea718b91 git | Not specified |
| CNA | Linux | Linux | affected b48c24c2d710cf34810c555dcef883a3d35a9c08 4385ddd654d90245eeb83b3cb539670ab5c85ba4 git | Not specified |
| CNA | Linux | Linux | affected 5.14 | Not specified |
| CNA | Linux | Linux | unaffected 5.14 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.212 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/a80b3b13786e9ab1c52b31a1f16c7d6708fa9220 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d5aa82da8f65562da996d184686db9d0ea718b91 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d566002de555b18cc395012c5c1cb8682fc6d2a9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3159c6fac43dc24b34d31971884d98a7a1bf4c4b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/54cab78df0375196aaec4e3109191653d21751df | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4385ddd654d90245eeb83b3cb539670ab5c85ba4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ad360a31092a870633ec255b96f50181628b4de0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.