CVE-2026-53186

Description

A flaw was found in the Linux kernel's Remote Direct Memory Access (RDMA) SCSI RDMA Protocol (SRP) component. A malicious or compromised SRP target on the InfiniBand/RoCE fabric can exploit this vulnerability by sending a specially crafted SRP response with an excessively large data length. This can lead to an out-of-bounds read when processing sense data, causing read faults and potentially a denial of service (DoS) on the system.

Understanding the Weakness (CWE)

Confidentiality,Integrity

Technical Impact: Read Memory; Modify Memory; Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.