PT-2026-44237 · Linux · Linux Kernel

Published

2026-05-28

·

Updated

2026-06-15

·

CVE-2026-46114

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the RDMA rxe driver where the atomic write reply() function in drivers/infiniband/sw/rxe/rxe resp.c unconditionally dereferences 8 bytes from the payload addr(pkt). The check rkey() function previously allowed ATOMIC WRITE requests with a length of zero, enabling a remote initiator to trigger a read of 8 bytes beyond the logical end of the packet into the skb->head tailroom. This results in a remote disclosure of kernel tailroom data, including kernel strings and partial kernel-direct-map pointer words, which are then written into the attacker's Memory Region (MR) via rxe mr do atomic write().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46114
OPENSUSE-SU-2026:10954-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:2310-1

Affected Products

Linux Kernel