PT-2026-61177 · Linux · Linux
CVE-2026-63860
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Prefer NLA NUL STRING
These attributes are evaluated as c-string (passed to strcmp), but
NLA STRING doesn't check for the presence of a 0 terminator.
Either this needs to switch to nla strcmp() and needs to adjust printf fmt
specifier to not use plain %s, or this needs to use NLA NUL STRING.
As the code has been this way for long time, it seems to me that userspace
does include the terminating nul, even tough its not enforced so far, and
thus NLA NUL STRING use is the simpler solution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux