Out-of-bounds read in Linux kernel - CVE-2026-45856
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ib_uverbs_post_send() when processing a user-supplied wqe_size value. A local user can provide a crafted small wqe_size value to disclose sensitive information.
An excessively large wqe_size value can also trigger a warning in the memory allocation path.
How to mitigate CVE-2026-45856
Sources
- https://git.kernel.org/stable/c/01c9b152647dc70dc06a4a2eff86ebb3b3c76075
- https://git.kernel.org/stable/c/1956f0a74ccf5dc9c3ef717f2985c3ed3400aab0
- https://git.kernel.org/stable/c/9b5ac1c15334d46c0dbd49d64a2257b929500163
- https://git.kernel.org/stable/c/9c15ec4cd4e7f57c6bbcb4e73e99290f150dd2a7
- https://git.kernel.org/stable/c/bef70ff9841990658610512b4a18e4a88c9b4df6
- https://git.kernel.org/stable/c/bf1feed1a7886af945f92890493aefd2b5c9928a
- https://git.kernel.org/stable/c/bf4454da8b1e712714628c0a0d6e7845bb40790a
- https://git.kernel.org/stable/c/d533425ac1f2925b4fc3e4ed9b9d72362cb23475