SB20260325115 - Exposure of sensitive information to an unauthorized actor in Linux kernel hw irdma driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-23335)
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper initialization of stack memory in the RDMA/irdma subsystem when handling user-space requests. A local user can trigger the creation of an address handle via the irdma_create_user_ah() function to disclose up to 4 bytes of kernel stack memory.
The uninitialized reserved field in the irdma_create_ah_resp structure is copied to user space without being zeroed, leading to a kernel stack information leak.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/14b47c07c69930254f549a17ee245c80a65b1609
- https://git.kernel.org/stable/c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
- https://git.kernel.org/stable/c/2fd37450d271d74b3847baed284f9cfdf198c6f8
- https://git.kernel.org/stable/c/74586c6da9ea222a61c98394f2fc0a604748438c
- https://git.kernel.org/stable/c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a
- https://git.kernel.org/stable/c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84