CVE-2026-23335

MEDIUM EPSS 2.4%
Published Mar 25, 20263mo ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Mar 25, 2026 3mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() struct irdma_create_ah_resp { // 8 bytes, no padding __u32 ah_id; // offset 0 - SET (uresp.ah_id = ah->sc_ah.ah_info.ah_idx) __u8 rsvd[4]; // offset 4 - NEVER SET <- LEAK }; rsvd[4]: 4 bytes of stack memory leaked unconditionally. Only ah_id is assigned before ib_respond_udata(). The reserved members of the structure were not zeroed.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-401

Affected Products 14

VendorProductVersionRange
linuxlinux_kernel*≥5.14.1  –  <5.15.203
linuxlinux_kernel*≥5.16  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.77
linuxlinux_kernel*≥6.13  –  <6.18.17
linuxlinux_kernel*≥6.19  –  <6.19.7
linuxlinux_kernel5.14any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/14b47c07c69930254f549a17ee245c80a65b1609
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1f70df004fdd944653013ccc2e1dfd472a693b46
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2fd37450d271d74b3847baed284f9cfdf198c6f8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74586c6da9ea222a61c98394f2fc0a604748438c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/14b47c07c69930254f549a17ee245c80a65b1609
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/1f70df004fdd944653013ccc2e1dfd472a693b46
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2fd37450d271d74b3847baed284f9cfdf198c6f8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74586c6da9ea222a61c98394f2fc0a604748438c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84
    Patch