Junglewise Threat Intelligence

CVE-2026-23243: Linux kernel RDMA/umad out-of-bounds write in ib_umad_write

CVE-2026-23243 · Severity: high · CVSS 7.8 · Published 2026-03-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem that could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system processes specifically crafted network management packets, leading to memory corruption. This could impact system stability and the confidentiality of data handled by high-performance networking hardware.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the RDMA/umad component of the Linux kernel. The function 'ib_umad_write' calculates 'data_len' based on user-provided 'count' and MAD header sizes without sufficient validation. A mismatch between the user MAD header size and RMPP header length can result in a negative 'data_len' value. When this value is passed to 'ib_create_send_mad()', it causes padding calculations to exceed segment sizes, triggering an out-of-bounds 'memset' in 'alloc_send_rmpp_list()'. This is a local attack vector requiring low privileges. Patches have been released across multiple stable kernel branches (e.g., 5.10.252, 5.15.202, 6.1.165, 6.6.128, 6.12.75, 6.18.14, 6.19.4).

Affected products

  • Linux Linux kernel 2.6.24 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.14, 6.19 to 6.19.4

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: advisory
  • 2026-02-26: patched: Patches applied to various stable branches.

References

Related threats