SB2026081582 - Out-of-bounds read in Linux kernel sw rxe driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74377)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an out-of-bounds read.
The vulnerability exists due to an out-of-bounds read in rxe_resp_check_length() and copy_data() when processing a receive WQE from a shared queue buffer mapped into userspace. A local user can modify WQE fields such as num_sge or sge entries during processing to cause an out-of-bounds read.
The issue affects the non-SRQ queue pair receive path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2e60378fb3c8b51c94103bb40014c4fe38fa5033
- https://git.kernel.org/stable/c/5420eebf3b3c162bfaf965f30e61cd1d689e5732
- https://git.kernel.org/stable/c/9fa785137303f7109c23dea779b8dedc67c9b531
- https://git.kernel.org/stable/c/a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b
- https://git.kernel.org/stable/c/d6ab440240a04b8737ee4c7bb21af9182e451733
- https://git.kernel.org/stable/c/fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78