PT-2026-61177 · Linux · Linux
CVE-2026-63860
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
8.4
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Prefer NLA NUL STRING
These attributes are evaluated as c-string (passed to strcmp), but
NLA STRING doesn't check for the presence of a 0 terminator.
Either this needs to switch to nla strcmp() and needs to adjust printf fmt
specifier to not use plain %s, or this needs to use NLA NUL STRING.
As the code has been this way for long time, it seems to me that userspace
does include the terminating nul, even tough its not enforced so far, and
thus NLA NUL STRING use is the simpler solution.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux