๐Ÿ” CVE Alert

CVE-2026-92525

UNKNOWN 0.0

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE. rxe_requester() consumes it in place via req_next_wqe() and calls copy_data(), which indexes &wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge. Only the kernel path bounds num_sge (validate_send_wr()); the user WQE is never checked, so a local unprivileged user can post a WQE with an out-of-range cur_sge or oversized num_sge and force an out-of-bounds read of the per-WQE sge array in copy_data() (vmalloc OOB read, local DoS). Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way get_srq_wqe() already guards SRQ entries, and bound cur_sge only when the WQE carries payload (dma.resid): copy_data() returns early on a zero-length copy before touching dma->sge[], so a zero-payload WQE -- the only kind a max_sge == 0 QP can post -- stays valid. Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8700e3e7c4857d28ebaa824509934556da0b3e76 < 69d3ccf6543f24c452a020c8028ca6f46cb1e8db 8700e3e7c4857d28ebaa824509934556da0b3e76 < 750bba6ce9bb0b11d6a166031c9728ae3f21765e 8700e3e7c4857d28ebaa824509934556da0b3e76 < c067aa7b231e91a18a1b3666201ab14dfb00347a 8700e3e7c4857d28ebaa824509934556da0b3e76 < 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62 8700e3e7c4857d28ebaa824509934556da0b3e76 < 5ec111ddc1f727c1e4580aea459842ae5a8359a5 8700e3e7c4857d28ebaa824509934556da0b3e76 < 126c757e4cd46f866ddc283143b58eb4d9bf52cd
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/69d3ccf6543f24c452a020c8028ca6f46cb1e8db git.kernel.org: https://git.kernel.org/stable/c/750bba6ce9bb0b11d6a166031c9728ae3f21765e git.kernel.org: https://git.kernel.org/stable/c/c067aa7b231e91a18a1b3666201ab14dfb00347a git.kernel.org: https://git.kernel.org/stable/c/13cb7160e5b791f5e3ecf9311cf32849fe7e9b62 git.kernel.org: https://git.kernel.org/stable/c/5ec111ddc1f727c1e4580aea459842ae5a8359a5 git.kernel.org: https://git.kernel.org/stable/c/126c757e4cd46f866ddc283143b58eb4d9bf52cd