CVE-2026-46145
גבוהה 7.8
תיאור (מקור, אנגלית)
In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Validate rx_hash_key_len Sashiko points out that rx_hash_key_len comes from a uAPI structure and is blindly passed to memcpy, allowing the userspace to trash kernel memory. Bounds check it so the memcpy cannot overflow.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-6/8/2026
- CWE
- CWE-787
מוצרים מושפעים
linux: linux kernel
קישורים
- https://git.kernel.org/stable/c/012796f9541fcd0c1fa8ae4da7eb4d83931ef838 Patch
- https://git.kernel.org/stable/c/11c1431d641e0e4e0529e96957995820600c7287 Patch
- https://git.kernel.org/stable/c/6dd2d4ad9c8429523b1c220c5132bd551c006425 Patch
- https://git.kernel.org/stable/c/7d7c9f0fcd19c4d2f0164347c58d49cafa961b72 Patch
- https://git.kernel.org/stable/c/7d94f155f354b961c598f71bafa804dceded513f Patch
- https://access.redhat.com/errata/RHSA-2026:27353
- https://access.redhat.com/errata/RHSA-2026:27354
- https://access.redhat.com/errata/RHSA-2026:27789
- https://access.redhat.com/errata/RHSA-2026:30129
- https://access.redhat.com/security/cve/CVE-2026-46145