Improper input validation in Linux kernel - CVE-2026-63860
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the RDMA/core netlink attribute handling in drivers/infiniband/core/iwpm_msg.c when processing netlink messages containing string attributes evaluated as c-strings without an enforced nul terminator. A local user can send a specially crafted netlink message to cause a denial of service.
How to mitigate CVE-2026-63860
Sources
- https://git.kernel.org/stable/c/137b5918931d4d05aa8ea8d3adf67f7224eef63c
- https://git.kernel.org/stable/c/5877c043398d5fa0e93919a3d837e5cd7a98a961
- https://git.kernel.org/stable/c/6ed3d14fc45d3da6025e7fe4a6a09066856698e2
- https://git.kernel.org/stable/c/87111356d58d86edb221ba144d261ed83a5b8bbe
- https://git.kernel.org/stable/c/abda65bdd13084c771842adaac1f652d0660dd82
- https://git.kernel.org/stable/c/c26a0052cceed4c4d380ee5808b699f937fb58d8
- https://git.kernel.org/stable/c/f2c7b39dde2e61df8157066969cc2a408cd3dcd9
- https://git.kernel.org/stable/c/fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf