CVE-2026-92525
CVE CVE-2026-92525EUVD EUVD-2026-82146Veröffentlicht 2026-09-17T16:10:30.000ZZuletzt geändert 2026-09-18T17:55:38.000ZCVSS 7.1
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE. rxe_requester() consumes it in place via req_next_wqe() and calls copy_data(), which indexes &wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge. Only the kernel path bounds num_sge (validate_send_wr()); the user WQE is never checked, so a local unprivileged user can post a WQE with an out-of-range cur_sge or oversized num_sge and force an out-of-bounds read of the per-WQE sge array in copy_data() (vmalloc OOB read, local DoS). Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way get_srq_wqe() already guards SRQ entries, and bound cur_sge only when the WQE carries payload (dma.resid): copy_data() returns early on a zero-length copy before touching dma->sge[], so a zero-payload WQE -- the only kind a max_sge == 0 QP can post -- stays valid. Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 6.6.157; patch: 0; patch: 6.12.110; 8700e3e7c4857d28ebaa824509934556da0b3e76 <c067aa7b231e91a18a1b3666201ab14dfb00347a; 4.8; 8700e3e7c4857d28ebaa824509934556da0b3e76 <750bba6ce9bb0b11d6a166031c9728ae3f21765e; 8700e3e7c4857d28ebaa824509934556da0b3e76 <126c757e4cd46f866ddc283143b58eb4d9bf52cd; 8700e3e7c4857d28ebaa824509934556da0b3e76 <5ec111ddc1f727c1e4580aea459842ae5a8359a5; 8700e3e7c4857d28ebaa824509934556da0b3e76 <69d3ccf6543f24c452a020c8028ca6f46cb1e8db; patch: 7.2.6; patch: 7.3-rc1; patch: 6.1.188; patch: 6.18.52; 8700e3e7c4857d28ebaa824509934556da0b3e76 <13cb7160e5b791f5e3ecf9311cf32849fe7e9b62
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.