{"id":"CVE-2026-74378","title":"RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe\n\nget_srq_wqe() reads wqe->dma.num_sge from the shared receive queue\nbuffer, which is mapped into userspace. It validat…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < c8db0e5ab0b6c540214c46c56aaac7cbcb0967fe","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < e48daa94ad2d406225b73491fc935064716f0ec7","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3cfa2a3adc51b7c57729961a03446962ff10e3d2","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < cd19a6345e3727adafafa5954b58b13c92e13b80","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3e07ea9579dc9553d2285c26c2823931358aa3b8","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 02558c86b6b761063e9399e6b939984500327ef1","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < b9800d7953d119bcc068c74587d48e4ba0313629","Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 22b8fbded65b8c441b634a185f8da67657df6c50","Linux 4.8"],"published":"2026-08-15","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:46.129Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-74378","references":[{"url":"https://git.kernel.org/stable/c/c8db0e5ab0b6c540214c46c56aaac7cbcb0967fe"},{"url":"https://git.kernel.org/stable/c/e48daa94ad2d406225b73491fc935064716f0ec7"},{"url":"https://git.kernel.org/stable/c/3cfa2a3adc51b7c57729961a03446962ff10e3d2"},{"url":"https://git.kernel.org/stable/c/cd19a6345e3727adafafa5954b58b13c92e13b80"},{"url":"https://git.kernel.org/stable/c/3e07ea9579dc9553d2285c26c2823931358aa3b8"},{"url":"https://git.kernel.org/stable/c/02558c86b6b761063e9399e6b939984500327ef1"},{"url":"https://git.kernel.org/stable/c/b9800d7953d119bcc068c74587d48e4ba0313629"},{"url":"https://git.kernel.org/stable/c/22b8fbded65b8c441b634a185f8da67657df6c50"}],"tags":["cve.org"],"epss":0.00143,"epssPercentile":0.03943,"ingestedAt":"2026-09-14T15:23:07.456Z","slug":"CVE-2026-74378","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe\n\nget_srq_wqe() reads wqe->dma.num_sge from the shared receive queue\nbuffer, which is mapped into userspace. It validates num_sge against\nmax_sge, but then re-reads the same field to calculate the memcpy\nsize. A concurrent userspace thread can modify num_sge between\nvalidation and use, causing a heap buffer overflow when copying the\nWQE into qp->resp.srq_wqe.\n\nRead num_sge into a local variable and use it for both the bounds\ncheck and the size calculation.\n\n## Affected\n\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < c8db0e5ab0b6c540214c46c56aaac7cbcb0967fe`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < e48daa94ad2d406225b73491fc935064716f0ec7`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3cfa2a3adc51b7c57729961a03446962ff10e3d2`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < cd19a6345e3727adafafa5954b58b13c92e13b80`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3e07ea9579dc9553d2285c26c2823931358aa3b8`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 02558c86b6b761063e9399e6b939984500327ef1`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < b9800d7953d119bcc068c74587d48e4ba0313629`\n- `Linux >= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 22b8fbded65b8c441b634a185f8da67657df6c50`\n- `Linux 4.8`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}