SB2026081561 - Integer overflow in Linux kernel ulp srpt driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-74394)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the immediate data length check in the RDMA/srpt subsystem when processing user-supplied immediate data received over the network. A remote attacker can send a specially crafted network request with an oversized length value to cause a denial of service.
The length field is user-controlled and may wrap the computed request size, bypassing the bounds check before a very large length is passed to sg_init_one().
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/067b9556eeb007f28b7c2033b4dcde5b6d88418f
- https://git.kernel.org/stable/c/07dec3f6dcb6c6cc891162d252b800eb0e6d5e8e
- https://git.kernel.org/stable/c/3efa5301137140a3ca3677a9098c0a93a0acfd49
- https://git.kernel.org/stable/c/65572fbd86033ae2370125593d59b8be34253aaf
- https://git.kernel.org/stable/c/72497172a4799119a0282a5eb5e2b8ddcc821921
- https://git.kernel.org/stable/c/c82c860f8c8e4f4f454c9f14d0ad0c0466965f7d
- https://git.kernel.org/stable/c/dcf7a986f377cce0749ed53f1d64195fbd5fdf91
- https://git.kernel.org/stable/c/eb4ecdf631fe00e8020bf461503cb9b7017ed796