CVE-2026-74346

Source
https://cve.org/CVERecord?id=CVE-2026-74346
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74346.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74346
Downstream
Published
2026-08-15T05:58:34Z
Modified
2026-08-18T03:31:26Z
Summary
RDMA/irdma: Fix OOB read during CQ MR registration
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Fix OOB read during CQ MR registration

Sashiko pointed out an unrelated bug during a previous patch: https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com

This change fixes the bug by eliminating the cqmr->split field which was not being set properly and instead just checks the CQ resize feature flag directly.

The cqmr->split field essentially tracks whether IRDMA_FEATURE_CQ_RESIZE is set, but it was not being set until CQ creation time, which is after CQ memory registration (the only other place where it is referenced).

As a result, it would always be false during MR registration and would therefore cause irdma_handle_q_mem to populate cqmr->shadow even for GEN_2 HW and beyond:

cqmr->shadow = (dma_addr_t)arr[req->cq_pages];

The issue is that for GEN_2 and beyond, req->cq_pages may be exactly equal to iwmr->page_cnt and therefore equal to the size of arr, which would cause an OOB read by one.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74346.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b48c24c2d710cf34810c555dcef883a3d35a9c08
Fixed
a80b3b13786e9ab1c52b31a1f16c7d6708fa9220
Fixed
3159c6fac43dc24b34d31971884d98a7a1bf4c4b
Fixed
ad360a31092a870633ec255b96f50181628b4de0
Fixed
d566002de555b18cc395012c5c1cb8682fc6d2a9
Fixed
54cab78df0375196aaec4e3109191653d21751df
Fixed
d5aa82da8f65562da996d184686db9d0ea718b91
Fixed
4385ddd654d90245eeb83b3cb539670ab5c85ba4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74346.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74346.json"