CVE-2026-46043
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Validate pad and ICRC before payloadsize() in rxercv
rxe_rcv() currently checks only that the incoming packet is at least
headersize(pkt) bytes long before payloadsize() is used.
However, payload_size() subtracts both the attacker-controlled BTH pad
field and RXEICRCSIZE from pkt->paylen:
payloadsize = pkt->paylen - offset[RXEPAYLOAD] - bth_pad(pkt)
- RXEICRCSIZE
This means a short packet can still make payload_size() underflow even
if it includes enough bytes for the fixed headers. Simply requiring
headersize(pkt) + RXEICRC_SIZE is not sufficient either, because a
packet with a forged non-zero BTH pad can still leave payload_size()
negative and pass an underflowed value to later receive-path users.
Fix this by validating pkt->paylen against the full minimum length
required by payloadsize(): headersize(pkt) + bth_pad(pkt) +
RXEICRCSIZE.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/2c0d71ef12f46c57d37bc571f3f2797db7eb50cc, https://git.kernel.org/stable/c/2fd4f8b749309a61c3f3f88ee8891d94f79e1240, https://git.kernel.org/stable/c/5fedefec757192dcaad29a664ac332c7601be144, https://git.kernel.org/stable/c/7244491dab347f648e661da96dc0febadd9daec3, https://git.kernel.org/stable/c/9b924f3a26b21330a837cfe72e819b6393bbeeaa, https://git.kernel.org/stable/c/c4376c672c3648d5bdc31dfffc329d07164f93c4, https://git.kernel.org/stable/c/e8ee0e792d475b1067c199ef0af1b6221fa6f43d, https://git.kernel.org/stable/c/f83519a4c122c9c7a850a2197648a9ff4c67c520, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46043.json, https://nvd.nist.gov/vuln/detail/CVE-2026-46043, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git