Junglewise Threat Intelligence

CVE-2026-45856: Linux Kernel RDMA out-of-bounds read in ib_uverbs_post_send

CVE-2026-45856 · Severity: info · CVSS 6.2 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem, which is used for high-speed data transfers between servers. A local user could exploit this flaw to read sensitive information from the system's memory that they should not have access to. This could lead to the exposure of private data or system secrets, potentially aiding further attacks.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's RDMA/uverbs implementation. The function ib_uverbs_post_send() fails to validate the 'wqe_size' parameter provided by userspace before using it in a kmalloc() call. If a user provides a size smaller than the expected 'struct ib_uverbs_send_wr', subsequent kernel operations on the allocated buffer will read beyond its bounds. This allows a local attacker to leak sensitive kernel heap memory to userspace. Additionally, providing an extremely large size can trigger kernel warnings and memory allocation failures. The issue has been resolved by enforcing a minimum size check for 'wqe_size'.

Affected products

  • Linux Linux Kernel Fixed in versions 01c9b15, 1956f0a, 9b5ac1c, 9c15ec4, bef70ff, bf1feed, bf4454d, d533425

Timeline

  • 2026-01-22: other: Patch authored
  • 2026-05-27: advisory: NVD publication date

References

Related threats