CVE-2026-31491 PUBLISHED

RDMA/irdma: Harden depth calculation functions

Assigner: Linux
Reserved: 09.03.2026 Published: 22.04.2026 Updated: 22.04.2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Harden depth calculation functions

An issue was exposed where OS can pass in U32_MAX for SQ/RQ/SRQ size. This can cause integer overflow and truncation of SQ/RQ/SRQ depth returning a success when it should have failed.

Harden the functions to do all depth calculations and boundary checking in u64 sizes.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 563e1feb5f6ed579acb55850f1bbb831aecf645a to 3f08351de5ca4f2f724b86ad252fbc21289467e1 (excl.)
  • affected from 563e1feb5f6ed579acb55850f1bbb831aecf645a to cbd852f5700eb3f64392452faf693ac45cae8281 (excl.)
  • affected from 563e1feb5f6ed579acb55850f1bbb831aecf645a to e37afcb56ae070477741fe2d6e61fc0c542cce2d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 6.18.21 to 6.18.* (incl.)
  • unaffected from 6.19.11 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References