RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe

Summary

CVECVE-2026-74378
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:39 UTC
Updated2026-08-15 06:22:39 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue buffer, which is mapped into userspace. It validates num_sge against max_sge, but then re-reads the same field to calculate the memcpy size. A concurrent userspace thread can modify num_sge between validation and use, causing a heap buffer overflow when copying the WQE into qp->resp.srq_wqe. Read num_sge into a local variable and use it for both the bounds check and the size calculation.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 3cfa2a3adc51b7c57729961a03446962ff10e3d2 git Not specified
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 cd19a6345e3727adafafa5954b58b13c92e13b80 git Not specified
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 3e07ea9579dc9553d2285c26c2823931358aa3b8 git Not specified
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 02558c86b6b761063e9399e6b939984500327ef1 git Not specified
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 b9800d7953d119bcc068c74587d48e4ba0313629 git Not specified
CNA Linux Linux affected 8700e3e7c4857d28ebaa824509934556da0b3e76 22b8fbded65b8c441b634a185f8da67657df6c50 git Not specified
CNA Linux Linux affected 4.8 Not specified
CNA Linux Linux unaffected 4.8 semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/22b8fbded65b8c441b634a185f8da67657df6c50 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/02558c86b6b761063e9399e6b939984500327ef1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3e07ea9579dc9553d2285c26c2823931358aa3b8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3cfa2a3adc51b7c57729961a03446962ff10e3d2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cd19a6345e3727adafafa5954b58b13c92e13b80 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b9800d7953d119bcc068c74587d48e4ba0313629 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report