CVE-2026-74346
CVE CVE-2026-74346EUVD EUVD-2026-59493Published 2026-08-15T05:58:34.000ZLast changed 2026-08-17T05:17:38.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix OOB read during CQ MR registration Sashiko pointed out an unrelated bug during a previous patch: https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com This change fixes the bug by eliminating the cqmr->split field which was not being set properly and instead just checks the CQ resize feature flag directly. The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE is set, but it was not being set until CQ creation time, which is _after_ CQ memory registration (the only other place where it is referenced). As a result, it would always be false during MR registration and would therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2 HW and beyond: cqmr->shadow = (dma_addr_t)arr[req->cq_pages]; The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal to iwmr->page_cnt and therefore equal to the size of arr, which would cause an OOB read by one.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.1.178; patch: 6.12.97; b48c24c2d710cf34810c555dcef883a3d35a9c08 <ad360a31092a870633ec255b96f50181628b4de0; patch: 7.1.5; patch: 5.15.212; patch: 7.2; b48c24c2d710cf34810c555dcef883a3d35a9c08 <3159c6fac43dc24b34d31971884d98a7a1bf4c4b; b48c24c2d710cf34810c555dcef883a3d35a9c08 <a80b3b13786e9ab1c52b31a1f16c7d6708fa9220; b48c24c2d710cf34810c555dcef883a3d35a9c08 <d5aa82da8f65562da996d184686db9d0ea718b91; b48c24c2d710cf34810c555dcef883a3d35a9c08 <54cab78df0375196aaec4e3109191653d21751df; 5.14; b48c24c2d710cf34810c555dcef883a3d35a9c08 <4385ddd654d90245eeb83b3cb539670ab5c85ba4; patch: 6.6.145; patch: 6.18.40; patch: 0; b48c24c2d710cf34810c555dcef883a3d35a9c08 <d566002de555b18cc395012c5c1cb8682fc6d2a9
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.