SB20260925108 - Out-of-bounds read in Linux kernel hw efa driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-93264)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory registration to be rejected.
The vulnerability exists due to an incorrect chunk length calculation in the EFA RDMA driver's pbl_chunk_list_create function when registering a memory region whose PBL page count is a multiple of 510. A local user can register such a memory region to cause memory registration to be rejected.
The issue can also result in an out-of-bounds access to the chunks array.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1d4b5902773475fc97151379b7e5f09cad0fa57b
- https://git.kernel.org/stable/c/229b42d7450c1cf96f45ec39ebb69211b06bc036
- https://git.kernel.org/stable/c/3982714e15512b83115897806dacc94899683420
- https://git.kernel.org/stable/c/489b28f2377afa70c18c45b06a6387f3d39bb123
- https://git.kernel.org/stable/c/665cd418b8561a099c3854443f8ad8ae751b72a0
- https://git.kernel.org/stable/c/932e5684906a090644a9061fae2d254041c3b8f2
- https://git.kernel.org/stable/c/aadf3f9b5edb7f0a77e9172b237d2e07c754829c
- https://git.kernel.org/stable/c/da7805f0211af19968584e621074f253ac07dba7