Junglewise Threat Intelligence

CVE-2026-92525: Linux kernel RDMA/rxe out-of-bounds read in copy_data

CVE-2026-92525 · Severity: high · CVSS 7.1 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA/rxe driver fails to validate user-supplied work queue elements (WQEs) before using them to index into memory arrays. A local, unprivileged user can craft a malicious WQE with out-of-range index values to trigger an out-of-bounds read in kernel memory, causing a denial of service. This impacts systems using the Soft RoCE (RDMA over Converged Ethernet) driver for high-performance networking.

Technical details

This is a bounds-checking vulnerability in the RDMA/rxe soft driver's requester path. When a user-space queue pair (QP) submits a send WQE via an mmap'd ring buffer, the kernel's rxe_requester() function consumes the WQE without validating the attacker-controlled num_sge and cur_sge fields. The copy_data() function then indexes the per-WQE sge array using these unchecked values, leading to a vmalloc out-of-bounds read. The attack requires local access and no special privileges. The fix bounds num_sge to qp->sq.max_sge and cur_sge (when payload exists) before array indexing. The vulnerability affects the RDMA/rxe driver since its introduction in kernel v2.6.36.

Affected products

  • Linux Linux kernel 2.6.36 and later (through the original patch date 2026-07-20)

Timeline

  • 2026-09-17: disclosed: Published on NVD
  • 2026-07-20: patched: Upstream fix committed by Leon Romanovsky

References

Related threats