CVE-2026-92525 PUBLISHED

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

Assigner: Linux
Reserved: 16.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

For a user QP, qp->sq.queue is a ring the application writes directly, so rxe_post_send() takes the is_user branch and only schedules send_task without validating the WQE. rxe_requester() consumes it in place via req_next_wqe() and calls copy_data(), which indexes &wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge. Only the kernel path bounds num_sge (validate_send_wr()); the user WQE is never checked, so a local unprivileged user can post a WQE with an out-of-range cur_sge or oversized num_sge and force an out-of-bounds read of the per-WQE sge array in copy_data() (vmalloc OOB read, local DoS).

Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way get_srq_wqe() already guards SRQ entries, and bound cur_sge only when the WQE carries payload (dma.resid): copy_data() returns early on a zero-length copy before touching dma->sge[], so a zero-payload WQE -- the only kind a max_sge == 0 QP can post -- stays valid.

Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to 69d3ccf6543f24c452a020c8028ca6f46cb1e8db (excl.)
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to 750bba6ce9bb0b11d6a166031c9728ae3f21765e (excl.)
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to c067aa7b231e91a18a1b3666201ab14dfb00347a (excl.)
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62 (excl.)
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to 5ec111ddc1f727c1e4580aea459842ae5a8359a5 (excl.)
  • affected from 8700e3e7c4857d28ebaa824509934556da0b3e76 to 126c757e4cd46f866ddc283143b58eb4d9bf52cd (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.8 is affected
  • unaffected from 0 to 4.8 (excl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References