Out-of-bounds read in Linux kernel - CVE-2026-93264
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause memory registration to be rejected.
The vulnerability exists due to an incorrect chunk length calculation in the EFA RDMA driver's pbl_chunk_list_create function when registering a memory region whose PBL page count is a multiple of 510. A local user can register such a memory region to cause memory registration to be rejected.
The issue can also result in an out-of-bounds access to the chunks array.
Affected software
How to mitigate CVE-2026-93264
External References
- https://git.kernel.org/stable/c/1d4b5902773475fc97151379b7e5f09cad0fa57b
- https://git.kernel.org/stable/c/229b42d7450c1cf96f45ec39ebb69211b06bc036
- https://git.kernel.org/stable/c/3982714e15512b83115897806dacc94899683420
- https://git.kernel.org/stable/c/489b28f2377afa70c18c45b06a6387f3d39bb123
- https://git.kernel.org/stable/c/665cd418b8561a099c3854443f8ad8ae751b72a0
- https://git.kernel.org/stable/c/932e5684906a090644a9061fae2d254041c3b8f2
- https://git.kernel.org/stable/c/aadf3f9b5edb7f0a77e9172b237d2e07c754829c
- https://git.kernel.org/stable/c/da7805f0211af19968584e621074f253ac07dba7