CVE-2026-23243Patch(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and trigger an out-of-bounds memset in alloc_send_rmpp_list(). Add an explicit check to reject negative data_len before creating the send buffer. KASAN splat: [ 211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0 [ 211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102 [ 211.365867] ib_create_send_mad+0xa01/0x11b0 [ 211.365887] ib_umad_write+0x853/0x1c80

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-06-23: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-03-18: 1Technical Details · 2026-06-23: 103-1806-23
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ChrisUK2026@chris_uk2026
    Patch

    CVE-2026-23243 affects Red Hat Enterprise Linux 7 Extended Lifecycle Support with CRITICAL kernel vulnerabilities, including DoS & memory corruption. Apply the official update from RHSA-2026:27729 reboot system: https://radar.offseq.com/threat/red-hat-security-advisory-kernel-security-bug-fix--c9a5a31cd7574f36 OffSeq #LinuxSecurity #RedHat #Vulnerability

    Post summary

    The post highlights CVE-2026-23243, a critical kernel vulnerability in Red Hat Enterprise Linux 7, and urges users to apply the RHSA-2026:27729 update and reboot.

    0000045
    23 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23243 In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-c… https://www.cve.org/CVERecord?id=CVE-2026-23243

    Post summary

    The CVE was fixed in the Linux kernel with a patch that rejects negative data_len in ib_umad_write; no PoC, exploit, or active exploitation details are provided.

    00000138
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.24--

Explore more