CVE-2026-53186
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/06/2026
Última modificación:
06/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
RDMA/srp: bound SRP_RSP sense copy by the received length<br />
<br />
srp_process_rsp() copies sense data from rsp->data + resp_data_len,<br />
where resp_data_len is the full 32-bit value supplied by the SRP target<br />
and is never checked against the number of bytes actually received<br />
(wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so<br />
at most 96 bytes are copied, but the source offset is not bounded.<br />
<br />
A malicious or compromised SRP target on the InfiniBand/RoCE fabric that<br />
the initiator has logged into can return an SRP_RSP with<br />
SRP_RSP_FLAG_SNSVALID set and a large resp_data_len. The receive buffer<br />
is allocated at the target-chosen max_ti_iu_len, so the source of the<br />
sense copy lands past the bytes actually received; with resp_data_len<br />
near 0xFFFFFFFF it is gigabytes past the buffer and the read faults.<br />
<br />
Copy the sense data only if it has not been truncated, that is, only if<br />
the response header, the response data, and the sense region fit within<br />
the bytes actually received; otherwise drop the sense and log. The<br />
in-tree iSER and NVMe-RDMA receive paths already bound their parse by<br />
wc->byte_len; this brings ib_srp into line with them.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.15 (incluyendo) | 5.10.259 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/0b9ee09d5e849591f17d98c078033dadea967293
- https://git.kernel.org/stable/c/0d64bc200ebe4f275b27438c6e593903e0b16fe1
- https://git.kernel.org/stable/c/13e91fd076306f5d0cdfa14f53d69e37274723c4
- https://git.kernel.org/stable/c/2015038195939eac54a1ee83c9d98ef1a8ccbbce
- https://git.kernel.org/stable/c/3523e53ff95f1837ec3f57ff7558532bcb2661b7
- https://git.kernel.org/stable/c/3889517c2ec7f364914aea8209abfff735f7ecde
- https://git.kernel.org/stable/c/ed77cc819ad631264787cade5ae5ec4c535ec6bb
- https://git.kernel.org/stable/c/f92a285db7ff6e598591ccbfb551be155c5f4d57



