Answer in brief
CVE-2026-74377 records a High severity (CVSS 7.8) vulnerability in RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8700e3e7c4857d28ebaa824509934556da0b3e76 <2e60378fb3c8b51c94103bb40014c4fe38fa5033 || >=8700e3e7c4857d28ebaa824509934556da0b3e76 <fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78 || >=8700e3e7c4857d28ebaa824509934556da0b3e76 <9fa785137303f7109c23dea779b8dedc67c9b531 || >=8700e3e7c4857d28ebaa824509934556da0b3e76 <5420eebf3b3c162bfaf965f30e61cd1d689e5732 || >=8700e3e7c4857d28ebaa824509934556da0b3e76 <a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b || >=8700e3e7c4857d28ebaa824509934556da0b3e76 <d6ab440240a04b8737ee4c7bb21af9182e451733 | 2e60378fb3c8b51c94103bb40014c4fe38fa5033, fc72fd61cc8b2e2e3e92ae4c0e9cc30c9a7ecb78, 9fa785137303f7109c23dea779b8dedc67c9b531, 5420eebf3b3c162bfaf965f30e61cd1d689e5732, a211b7904aed365e4e4f08a48ec6e6dd1ea7b16b, d6ab440240a04b8737ee4c7bb21af9182e451733 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path For non-SRQ QPs, the responder reads WQE fields directly from the shared queue buffer mapped into userspace. This allows a malicious user to modify fields like num_sge or sge entries while the kernel is processing the WQE, leading to out-of-bounds reads in rxe_resp_check_length() and copy_data(). Introduce get_recv_wqe() that validates num_sge and copies the WQE to a kernel-local buffer before processing, matching the approach already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is reused since SRQ and non-SRQ paths are mutually exclusive per QP.
Quoted source text, attributed separately from HOL analysis.