Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

For a user QP, qp->sq.queue is a ring the application writes directly,
so rxe_post_send() takes the is_user branch and only schedules send_task
without validating the WQE. rxe_requester() consumes it in place via
req_next_wqe() and calls copy_data(), which indexes
&wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge.
Only the kernel path bounds num_sge (validate_send_wr()); the user WQE
is never checked, so a local unprivileged user can post a WQE with an
out-of-range cur_sge or oversized num_sge and force an out-of-bounds
read of the per-WQE sge array in copy_data() (vmalloc OOB read, local
DoS).

Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way
get_srq_wqe() already guards SRQ entries, and bound cur_sge only when
the WQE carries payload (dma.resid): copy_data() returns early on a
zero-length copy before touching dma->sge[], so a zero-payload WQE --
the only kind a max_sge == 0 QP can post -- stays valid.

Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local denial of service via out‑of‑bounds read in RDMA/rxe
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s RDMA/rxe driver, the contents of a user‑mode work‑queue entry are copied into the driver’s scatter‑list array without validating the num_sge or cur_sge fields. Since the driver can read beyond the bounds of the array, a malicious value crafted by the user causes an out‑of‑bounds read. The fault does not directly provide control‑flow hijack or privilege escalation, but it can corrupt kernel memory and crash the calling process, leading to a local denial‑of‑service condition.

Affected Systems

Any Linux system that runs a kernel build including the RDMA/rxe driver is potentially affected. Systems that have merged the bound‑check patch or backported it are not impacted. No specific version range is provided in the CNA data, so the vulnerability applies to all kernel releases prior to the patch merge.

Risk and Exploitability

The CVSS score of 7.1 places the flaw in the high‑severity category. The EPSS score is reported as less than 1%, indicating a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring an unprivileged user with access to post RDMA send requests; no privilege escalation is achieved. Attacking this vulnerability can trigger a kernel OOB read and cause a crash or denial of service for the target process, but the kernel remains stable and an attacker cannot gain further access.

Generated by OpenCVE AI on September 19, 2026 at 22:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the RDMA/rxe num_sge/cur_sge bounds‑check patch
  • Reboot the system so that the new kernel version takes effect
  • If RDMA functionality is not required, remove or blacklist the rxe kernel module from autoloading
  • As a containment measure, restrict RDMA device access to privileged accounts only through udev rules or permission changes

Generated by OpenCVE AI on September 19, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE. rxe_requester() consumes it in place via req_next_wqe() and calls copy_data(), which indexes &wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge. Only the kernel path bounds num_sge (validate_send_wr()); the user WQE is never checked, so a local unprivileged user can post a WQE with an out-of-range cur_sge or oversized num_sge and force an out-of-bounds read of the per-WQE sge array in copy_data() (vmalloc OOB read, local DoS). Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way get_srq_wqe() already guards SRQ entries, and bound cur_sge only when the WQE carries payload (dma.resid): copy_data() returns early on a zero-length copy before touching dma->sge[], so a zero-payload WQE -- the only kind a max_sge == 0 QP can post -- stays valid. Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Title RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:38.904Z

Reserved: 2026-09-16T12:21:13.875Z

Link: CVE-2026-92525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:55.540

Modified: 2026-09-18T18:18:14.300

Link: CVE-2026-92525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses