Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-53186

RDMA/srp: bound SRP_RSP sense copy by the received length
Back to all
CVE

CVE-2026-53186

RDMA/srp: bound SRP_RSP sense copy by the received length

In the Linux kernel, the following vulnerability has been resolved:

RDMA/srp: bound SRP_RSP sense copy by the received length

srpprocessrsp() copies sense data from rsp->data + respdatalen,

where respdatalen is the full 32-bit value supplied by the SRP target

and is never checked against the number of bytes actually received

(wc->bytelen). The copy length is bounded to SCSISENSE_BUFFERSIZE, so

at most 96 bytes are copied, but the source offset is not bounded.

A malicious or compromised SRP target on the InfiniBand/RoCE fabric that

the initiator has logged into can return an SRP_RSP with

SRPRSPFLAGSNSVALID set and a large respdata_len. The receive buffer

is allocated at the target-chosen maxtiiu_len, so the source of the

sense copy lands past the bytes actually received; with respdatalen

near 0xFFFFFFFF it is gigabytes past the buffer and the read faults.

Copy the sense data only if it has not been truncated, that is, only if

the response header, the response data, and the sense region fit within

the bytes actually received; otherwise drop the sense and log. The

in-tree iSER and NVMe-RDMA receive paths already bound their parse by

wc->bytelen; this brings ibsrp into line with them.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0b9ee09d5e849591f17d98c078033dadea967293, https://git.kernel.org/stable/c/0d64bc200ebe4f275b27438c6e593903e0b16fe1, https://git.kernel.org/stable/c/13e91fd076306f5d0cdfa14f53d69e37274723c4, https://git.kernel.org/stable/c/2015038195939eac54a1ee83c9d98ef1a8ccbbce, https://git.kernel.org/stable/c/3523e53ff95f1837ec3f57ff7558532bcb2661b7, https://git.kernel.org/stable/c/3889517c2ec7f364914aea8209abfff735f7ecde, https://git.kernel.org/stable/c/ed77cc819ad631264787cade5ae5ec4c535ec6bb, https://git.kernel.org/stable/c/f92a285db7ff6e598591ccbfb551be155c5f4d57, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53186.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53186, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00544%
EPSS Percentile
0.42114%
Introduced Version
aef9ec39c47f0cece886ddd6b53c440321e0b2a6,2.6.15,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
13e91fd076306f5d0cdfa14f53d69e37274723c4,5.10.259,5.15.210,6.1.176,6.6.143,6.12.94,6.18.36,7.0.13,6.1.176-1,5.10.259-1,6.1.176-1~deb11u1,6.12.94-1,0:5.10.259-258.1043.amzn2,0:1.0-0.amzn2,6.12.95-r0,6.18.38-r0,6.18.36-r0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading