SB20260727303 - Out-of-bounds read in Linux kernel ulp rtrs driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64269)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to an out-of-bounds read in rdma_write_sg when processing an RTRS READ response with an attacker-controlled descriptor length. A remote attacker can advertise a crafted desc[0].len value larger than max_chunk_size to disclose sensitive information or cause a denial of service.
With no IOMMU or in passthrough mode, adjacent host memory may be returned to the peer; with a translating IOMMU, the out-of-range access is expected to fault and abort the connection.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc
- https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667
- https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb
- https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da
- https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66
- https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1
- https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f