CVE-2026-53186
Description
A flaw was found in the Linux kernel's Remote Direct Memory Access (RDMA) SCSI RDMA Protocol (SRP) component. A malicious or compromised SRP target on the InfiniBand/RoCE fabric can exploit this vulnerability by sending a specially crafted SRP response with an excessively large data length. This can lead to an out-of-bounds read when processing sense data, causing read faults and potentially a denial of service (DoS) on the system.
Understanding the Weakness (CWE)
Confidentiality,Integrity
Technical Impact: Read Memory; Modify Memory; Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.