CVE-2026-46145
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/05/2026
Last modified:
30/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
RDMA/mana: Validate rx_hash_key_len<br />
<br />
Sashiko points out that rx_hash_key_len comes from a uAPI structure and is<br />
blindly passed to memcpy, allowing the userspace to trash kernel<br />
memory. Bounds check it so the memcpy cannot overflow.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/012796f9541fcd0c1fa8ae4da7eb4d83931ef838
- https://git.kernel.org/stable/c/11c1431d641e0e4e0529e96957995820600c7287
- https://git.kernel.org/stable/c/6dd2d4ad9c8429523b1c220c5132bd551c006425
- https://git.kernel.org/stable/c/7d7c9f0fcd19c4d2f0164347c58d49cafa961b72
- https://git.kernel.org/stable/c/7d94f155f354b961c598f71bafa804dceded513f



