Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-92525NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]

For a user QP, qp->sq.queue is a ring the application writes directly,
so rxe_post_send() takes the is_user branch and only schedules send_task
without validating the WQE. rxe_requester() consumes it in place via
req_next_wqe() and calls copy_data(), which indexes
&wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge.
Only the kernel path bounds num_sge (validate_send_wr()); the user WQE
is never checked, so a local unprivileged user can post a WQE with an
out-of-range cur_sge or oversized num_sge and force an out-of-bounds
read of the per-WQE sge array in copy_data() (vmalloc OOB read, local
DoS).

Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way
get_srq_wqe() already guards SRQ entries, and bound cur_sge only when
the WQE carries payload (dma.resid): copy_data() returns early on a
zero-length copy before touching dma->sge[], so a zero-payload WQE --
the only kind a max_sge == 0 QP can post -- stays valid.

Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Severity Level
HIGH(7.1)
Published Date
Sep 17, 2026
Last Modified
Sep 18, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.16%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 7.1 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < 69d3ccf6543f24c452a020c8028ca6f46cb1e8db
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < 750bba6ce9bb0b11d6a166031c9728ae3f21765e
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < c067aa7b231e91a18a1b3666201ab14dfb00347a
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < 5ec111ddc1f727c1e4580aea459842ae5a8359a5
  • Linux Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 and < 126c757e4cd46f866ddc283143b58eb4d9bf52cd
  • Linux Linux >= 4.8
Patched Versions
  • Linux Linux 69d3ccf6543f24c452a020c8028ca6f46cb1e8db
  • Linux Linux 750bba6ce9bb0b11d6a166031c9728ae3f21765e
  • Linux Linux c067aa7b231e91a18a1b3666201ab14dfb00347a
  • Linux Linux 13cb7160e5b791f5e3ecf9311cf32849fe7e9b62
  • Linux Linux 5ec111ddc1f727c1e4580aea459842ae5a8359a5
  • Linux Linux 126c757e4cd46f866ddc283143b58eb4d9bf52cd
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.