PT-2026-26046 · Linux+3 · Linux Kernel+3

·

CVE-2026-23243

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s RDMA/umad component where a negative data len value can occur in the ib umad write function. This happens when there is a mismatch between the user-controlled MAD header size and the RMPP header length. The negative data len can then lead to an out-of-bounds write in the alloc send rmpp list() function via an incorrect padding calculation within ib create send mad(). The issue is addressed by adding a check to reject negative data len values before creating the send buffer. The function ib umad write computes data len from a user-controlled count and MAD header sizes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:18134
ALSA-2026:18587
ALSA-2026:21706
ALSA-2026:21745
AZL-80004
BDU:2026-11665
CVE-2026-23243
ECHO-484C-4982-56D6
OESA-2026-1831
OESA-2026-2579
OESA-2026-2581
OPENSUSE-SU-2026:20572-1
RHSA-2026:13936
RHSA-2026:14137
RHSA-2026:14339
RHSA-2026:15883
RHSA-2026:18134
RHSA-2026:18587
RHSA-2026:19521
RHSA-2026:19875
RHSA-2026:20593
RHSA-2026:21209
RHSA-2026:21706
RHSA-2026:21745
RHSA-2026:26535
RHSA-2026:26570
RHSA-2026:27729
RHSA-2026:41236
SUSE-SU-2026:1342-1
SUSE-SU-2026:1557-1
SUSE-SU-2026:1563-1
SUSE-SU-2026:1573-1
SUSE-SU-2026:1574-1
SUSE-SU-2026:1575-1
SUSE-SU-2026:1606-1
SUSE-SU-2026:1643-1
SUSE-SU-2026:1661-1
SUSE-SU-2026:1668-1
SUSE-SU-2026:1777-1
SUSE-SU-2026:21114-1
SUSE-SU-2026:21123-1
SUSE-SU-2026:21230-1
SUSE-SU-2026:21237-1
SUSE-SU-2026:21255-1
SUSE-SU-2026:2131-1
SUSE-SU-2026:2134-1
SUSE-SU-2026:21352-1
SUSE-SU-2026:21361-1
SUSE-SU-2026:2137-1
SUSE-SU-2026:2141-1
SUSE-SU-2026:2148-1
SUSE-SU-2026:2149-1
SUSE-SU-2026:2153-1
SUSE-SU-2026:2158-1
SUSE-SU-2026:2159-1
SUSE-SU-2026:2168-1
SUSE-SU-2026:2172-1
SUSE-SU-2026:2176-1
SUSE-SU-2026:2178-1
SUSE-SU-2026:2181-1
SUSE-SU-2026:21886-1
SUSE-SU-2026:21887-1
SUSE-SU-2026:21888-1
SUSE-SU-2026:21889-1
SUSE-SU-2026:2189-1
SUSE-SU-2026:21890-1
SUSE-SU-2026:21891-1
SUSE-SU-2026:21892-1
SUSE-SU-2026:21893-1
SUSE-SU-2026:21894-1
SUSE-SU-2026:21896-1
SUSE-SU-2026:21900-1
SUSE-SU-2026:21901-1
SUSE-SU-2026:21902-1
SUSE-SU-2026:21903-1
SUSE-SU-2026:21904-1
SUSE-SU-2026:21905-1
SUSE-SU-2026:21906-1
SUSE-SU-2026:21907-1
SUSE-SU-2026:21908-1
SUSE-SU-2026:21910-1
SUSE-SU-2026:21921-1
SUSE-SU-2026:21922-1
SUSE-SU-2026:21923-1
SUSE-SU-2026:21924-1
SUSE-SU-2026:21925-1
SUSE-SU-2026:21926-1
SUSE-SU-2026:21927-1
SUSE-SU-2026:21928-1
SUSE-SU-2026:21929-1
SUSE-SU-2026:21930-1
SUSE-SU-2026:21932-1
SUSE-SU-2026:21933-1
SUSE-SU-2026:21934-1
SUSE-SU-2026:21935-1
SUSE-SU-2026:21936-1
SUSE-SU-2026:21937-1
SUSE-SU-2026:21938-1
SUSE-SU-2026:21939-1
SUSE-SU-2026:21940-1
SUSE-SU-2026:21942-1
SUSE-SU-2026:21956-1
SUSE-SU-2026:21958-1
SUSE-SU-2026:21959-1
SUSE-SU-2026:21960-1
SUSE-SU-2026:21962-1
SUSE-SU-2026:21963-1
SUSE-SU-2026:21969-1
SUSE-SU-2026:21970-1
SUSE-SU-2026:21972-1
SUSE-SU-2026:21974-1
SUSE-SU-2026:21979-1
SUSE-SU-2026:21982-1
SUSE-SU-2026:21983-1
SUSE-SU-2026:2199-1
SUSE-SU-2026:22030-1
SUSE-SU-2026:22031-1
SUSE-SU-2026:22033-1
SUSE-SU-2026:22035-1
SUSE-SU-2026:22038-1
SUSE-SU-2026:22039-1
SUSE-SU-2026:22040-1
SUSE-SU-2026:22042-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu