---
id: CVE-2026-23335
title: 'RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()

  struct irdma_create_ah_resp {  // 8 bytes, no padding
      __u32 ah_id;               // offset 0 - SET (ure…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    1f70df004fdd944653013ccc2e1dfd472a693b46
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    14b47c07c69930254f549a17ee245c80a65b1609
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    2fd37450d271d74b3847baed284f9cfdf198c6f8
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    cfe962216c164fe2b1c1fb6ac925a7413f5abc84
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    c9bd0007c4bdb7806bbd323287e50f9cf467c51a
  - >-
    Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 <
    74586c6da9ea222a61c98394f2fc0a604748438c
  - Linux 5.14
published: '2026-03-25'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:45:37.563Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23335'
references:
  - url: 'https://git.kernel.org/stable/c/1f70df004fdd944653013ccc2e1dfd472a693b46'
  - url: 'https://git.kernel.org/stable/c/14b47c07c69930254f549a17ee245c80a65b1609'
  - url: 'https://git.kernel.org/stable/c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8'
  - url: 'https://git.kernel.org/stable/c/2fd37450d271d74b3847baed284f9cfdf198c6f8'
  - url: 'https://git.kernel.org/stable/c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84'
  - url: 'https://git.kernel.org/stable/c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a'
  - url: 'https://git.kernel.org/stable/c/74586c6da9ea222a61c98394f2fc0a604748438c'
tags:
  - cve.org
epss: 0.00125
epssPercentile: 0.02566
ingestedAt: '2026-09-08T15:33:26.993Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()

struct irdma_create_ah_resp {  // 8 bytes, no padding
    __u32 ah_id;               // offset 0 - SET (uresp.ah_id = ah->sc_ah.ah_info.ah_idx)
    __u8  rsvd[4];             // offset 4 - NEVER SET <- LEAK
};

rsvd[4]: 4 bytes of stack memory leaked unconditionally. Only ah_id is assigned before ib_respond_udata().

The reserved members of the structure were not zeroed.

## Affected

- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < 1f70df004fdd944653013ccc2e1dfd472a693b46`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < 14b47c07c69930254f549a17ee245c80a65b1609`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < 1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < 2fd37450d271d74b3847baed284f9cfdf198c6f8`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < cfe962216c164fe2b1c1fb6ac925a7413f5abc84`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < c9bd0007c4bdb7806bbd323287e50f9cf467c51a`
- `Linux >= b48c24c2d710cf34810c555dcef883a3d35a9c08 < 74586c6da9ea222a61c98394f2fc0a604748438c`
- `Linux 5.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
