Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ

srp_recv_done() passes wc->byte_len to srp_process_rsp(). It passes
nothing to srp_process_cred_req() and srp_process_aer_req(), which read
fixed-size fields from the receive buffer without checking that those
fields were received.

The buffer size is max_ti_iu_len, which comes from the login response
and is not validated. A target that advertises 8 and then sends an
8-byte SRP_CRED_REQ makes the initiator read req->tag from beyond the
end of the buffer. req->tag is copied into the SRP_CRED_RSP and sent
back, so those bytes reach the target. SRP_AER_REQ behaves the same way
and also reads req->lun.

The leak is 8 bytes per response. max_ti_iu_len also decides which slab
cache the buffer comes from. With 8 the buffer is a kmalloc-8 object and
the read is entirely outside it:

BUG: KASAN: slab-out-of-bounds in srp_recv_done+0x172b/0x1aa0
Read of size 8 at addr ffff888104714da8 by task kworker/u8:3/50
which belongs to the cache kmalloc-8 of size 8
The buggy address is located 0 bytes to the right of
allocated 8-byte region [ffff888104714da0, ffff888104714da8)

Without KASAN the returned bytes are whatever is next in the slab. One
run returned ".strtab".

rsp->data[3] in srp_process_rsp() has the same problem: only
resp_data_len is checked before it is read.

Drop a request that is shorter than the structure being parsed, and
check byte_len before the tsk_mgmt read.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via heap over‑read in RDMA SRP driver
Action: Apply Patch
AI Analysis

Impact

The flaw arises when the RDMA SRP driver processes a truncated SRP_CRED_REQ or SRP_AER_REQ packet. The driver forwards a received byte length ("wc->byte_len") to a function that expects a full structure, then reads fixed‑size fields without validating that the packets contain those fields. An attacker can send a request that declares a small size (e.g., 8 bytes) but still contains longer data. The driver then copies data past the end of the allocated buffer and sends the leaked bytes back to the initiator. Each response can expose up to eight bytes of kernel heap memory, potentially revealing pointers or other internal information that could aid further attacks. The vulnerability is purely an information‑leak; it does not provide direct code execution or privilege escalation.

Affected Systems

The issue resides in the Linux kernel’s RDMA/SRP implementation. All kernel releases prior to the back‑ported fix are affected, regardless of distribution. The patch commits listed in the references (starting at 001adf2fe87d1ab6…) contain the defensive changes; any system running a kernel that has not incorporated those commits suffers from the exploitation.

Risk and Exploitability

The EPSS score is reported as less than 1 %, implying a very low probability of widespread exploitation. The vulnerability is not included in the CISA KEV catalog, and no exploit code has been published. Successful exploitation requires an attacker with network access to a host that exposes the SRP RDMA service and the ability to send malformed SRP packets, limiting the threat surface. However, the information disclosed could assist a more advanced attacker in enumerating kernel objects or crafting subsequent attacks. While the immediate risk is moderate, it is non‑negligible for systems with exposed RDMA interfaces.

Generated by OpenCVE AI on September 19, 2026 at 15:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the SRP heap‑over‑read fix (commits 001adf2fe87d1ab6 and related changes).
  • If a kernel update is not yet possible, disable the SRP RDMA driver or unload it with a modprobe command.
  • Block or filter SRP RDMA traffic at the network boundary so that malformed packets cannot reach the vulnerable driver.

Generated by OpenCVE AI on September 19, 2026 at 15:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ srp_recv_done() passes wc->byte_len to srp_process_rsp(). It passes nothing to srp_process_cred_req() and srp_process_aer_req(), which read fixed-size fields from the receive buffer without checking that those fields were received. The buffer size is max_ti_iu_len, which comes from the login response and is not validated. A target that advertises 8 and then sends an 8-byte SRP_CRED_REQ makes the initiator read req->tag from beyond the end of the buffer. req->tag is copied into the SRP_CRED_RSP and sent back, so those bytes reach the target. SRP_AER_REQ behaves the same way and also reads req->lun. The leak is 8 bytes per response. max_ti_iu_len also decides which slab cache the buffer comes from. With 8 the buffer is a kmalloc-8 object and the read is entirely outside it: BUG: KASAN: slab-out-of-bounds in srp_recv_done+0x172b/0x1aa0 Read of size 8 at addr ffff888104714da8 by task kworker/u8:3/50 which belongs to the cache kmalloc-8 of size 8 The buggy address is located 0 bytes to the right of allocated 8-byte region [ffff888104714da0, ffff888104714da8) Without KASAN the returned bytes are whatever is next in the slab. One run returned ".strtab". rsp->data[3] in srp_process_rsp() has the same problem: only resp_data_len is checked before it is read. Drop a request that is shorter than the structure being parsed, and check byte_len before the tsk_mgmt read.
Title RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:29.045Z

Reserved: 2026-09-11T19:38:34.800Z

Link: CVE-2026-90307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:28.377

Modified: 2026-09-17T17:17:28.377

Link: CVE-2026-90307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor