PT-2026-61177 · Linux · Linux

CVE-2026-63860

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
RDMA/core: Prefer NLA NUL STRING
These attributes are evaluated as c-string (passed to strcmp), but NLA STRING doesn't check for the presence of a 0 terminator.
Either this needs to switch to nla strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA NUL STRING.
As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA NUL STRING use is the simpler solution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63860

Affected Products

Linux