๐Ÿ” CVE Alert

CVE-2026-74378

UNKNOWN 0.0

RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue buffer, which is mapped into userspace. It validates num_sge against max_sge, but then re-reads the same field to calculate the memcpy size. A concurrent userspace thread can modify num_sge between validation and use, causing a heap buffer overflow when copying the WQE into qp->resp.srq_wqe. Read num_sge into a local variable and use it for both the bounds check and the size calculation.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8700e3e7c4857d28ebaa824509934556da0b3e76 < 3cfa2a3adc51b7c57729961a03446962ff10e3d2 8700e3e7c4857d28ebaa824509934556da0b3e76 < cd19a6345e3727adafafa5954b58b13c92e13b80 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3e07ea9579dc9553d2285c26c2823931358aa3b8 8700e3e7c4857d28ebaa824509934556da0b3e76 < 02558c86b6b761063e9399e6b939984500327ef1 8700e3e7c4857d28ebaa824509934556da0b3e76 < b9800d7953d119bcc068c74587d48e4ba0313629 8700e3e7c4857d28ebaa824509934556da0b3e76 < 22b8fbded65b8c441b634a185f8da67657df6c50
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3cfa2a3adc51b7c57729961a03446962ff10e3d2 git.kernel.org: https://git.kernel.org/stable/c/cd19a6345e3727adafafa5954b58b13c92e13b80 git.kernel.org: https://git.kernel.org/stable/c/3e07ea9579dc9553d2285c26c2823931358aa3b8 git.kernel.org: https://git.kernel.org/stable/c/02558c86b6b761063e9399e6b939984500327ef1 git.kernel.org: https://git.kernel.org/stable/c/b9800d7953d119bcc068c74587d48e4ba0313629 git.kernel.org: https://git.kernel.org/stable/c/22b8fbded65b8c441b634a185f8da67657df6c50