Out-of-bounds read in Linux kernel - CVE-2026-46114
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in atomic_write_reply() in the RDMA rxe responder when processing a crafted ATOMIC_WRITE request with a zero-length logical payload. A remote attacker can send a specially crafted ATOMIC_WRITE request to disclose sensitive information.
The issue can leak kernel tailroom bytes into the attacker's memory region, including recognizable kernel strings and partial pointer words.
How to mitigate CVE-2026-46114
Sources
- https://git.kernel.org/stable/c/105bf79a23b85cf3a761d18a4f3e10ce88526bc1
- https://git.kernel.org/stable/c/1114c87aa6f195cf07da55a27b2122ae26557b26
- https://git.kernel.org/stable/c/539cabb7b2d8ba70f55bba91db55faef11c2a6d7
- https://git.kernel.org/stable/c/7ec1ed4747f5f99f8b797bb438c5efd36079fad5
- https://git.kernel.org/stable/c/d415fce3fcde6d7aeea6c25362a395b905811452