Home

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() struct irdma_create_ah_resp { // 8 bytes, no padding __u32 ah_id; // offset 0 - SET (uresp.ah_id = ah->sc_ah.ah_info.ah_idx) __u8 rsvd[4]; // offset 4 - NEVER SET <- LEAK }; rsvd[4]: 4 bytes of stack memory leaked unconditionally. Only ah_id is assigned before ib_respond_udata(). The reserved members of the structure were not zeroed.

PUBLISHED Reserved 2026-01-13 | Published 2026-03-25 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 1f70df004fdd944653013ccc2e1dfd472a693b46
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 14b47c07c69930254f549a17ee245c80a65b1609
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 2fd37450d271d74b3847baed284f9cfdf198c6f8
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before cfe962216c164fe2b1c1fb6ac925a7413f5abc84
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before c9bd0007c4bdb7806bbd323287e50f9cf467c51a
affected

b48c24c2d710cf34810c555dcef883a3d35a9c08 (git) before 74586c6da9ea222a61c98394f2fc0a604748438c
affected

Default status
affected

5.14
affected

Any version before 5.14
unaffected

5.15.203 (semver)
unaffected

6.1.167 (semver)
unaffected

6.6.130 (semver)
unaffected

6.12.77 (semver)
unaffected

6.18.17 (semver)
unaffected

6.19.7 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/1f70df004fdd944653013ccc2e1dfd472a693b46

git.kernel.org/...c/14b47c07c69930254f549a17ee245c80a65b1609

git.kernel.org/...c/1b1fac4c7a3ab7f52e9cfb91e5c91216646ca4d8

git.kernel.org/...c/2fd37450d271d74b3847baed284f9cfdf198c6f8

git.kernel.org/...c/cfe962216c164fe2b1c1fb6ac925a7413f5abc84

git.kernel.org/...c/c9bd0007c4bdb7806bbd323287e50f9cf467c51a

git.kernel.org/...c/74586c6da9ea222a61c98394f2fc0a604748438c

cve.org (CVE-2026-23335)

nvd.nist.gov (CVE-2026-23335)

Download JSON