CVE-2026-31491

MEDIUM

RDMA/irdma: Harden depth calculation functions

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Harden depth calculation functions An issue was exposed where OS can pass in U32_MAX for SQ/RQ/SRQ size. This can cause integer overflow and truncation of SQ/RQ/SRQ depth returning a success when it should have failed. Harden the functions to do all depth calculations and boundary checking in u64 sizes.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (11)
Linux/Linux < 6.18
Linux/Linux 563e1feb5f6ed579acb55850f1bbb831aecf645a - 3f08351de5ca4f2f724b86ad252fbc21289467e1
Linux/Linux 563e1feb5f6ed579acb55850f1bbb831aecf645a - cbd852f5700eb3f64392452faf693ac45cae8281
Linux/Linux 563e1feb5f6ed579acb55850f1bbb831aecf645a - e37afcb56ae070477741fe2d6e61fc0c542cce2d
Linux/Linux 6.18
Linux/Linux 6.18.21 - 6.18.*
Linux/Linux 6.19.11 - 6.19.*
Linux/Linux 7.0
linux/linux_kernel 6.18
linux/linux_kernel 7.0 rc1 (7 CPE variants)
... and 1 more
Published Apr 22, 2026
Tracked Since Apr 22, 2026