CVE-2026-43184 (GCVE-0-2026-43184)
Vulnerability from cvelistv5
Published
2026-05-06 11:27
Modified
2026-08-05 12:26
Summary
In the Linux kernel, the following vulnerability has been resolved: rnbd-srv: Zero the rsp buffer before using it Before using the data buffer to send back the response message, zero it completely. This prevents any stray bytes to be picked up by the client side when there the message is exchanged between different protocol versions.
Impacted products
Vendor Product Version
Linux Linux Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Version: 2de6c8de192b9341ffa5e84afe1ce6196d4eef41
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/block/rnbd/rnbd-srv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e4272754063d52c9ad0169865add8816ba696471",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "e2cacec7d4291300a282feb3af8eba57b93b15aa",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "b646e54d23b9b592d612a2036aab14e0f6c14206",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "30868a6a5238849d554295aff3ce61d242d7fad8",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "7aac0a30dcf41cdb510526740d9a2ab1520c5d98",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "c94ede3c436dfbd9cedd9cb69f604f6fc901b6a2",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "852475278ca5e96e0c0275950e1a84203e602b33",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            },
            {
              "lessThan": "69d26698e4fd44935510553809007151b2fe4db5",
              "status": "affected",
              "version": "2de6c8de192b9341ffa5e84afe1ce6196d4eef41",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/block/rnbd/rnbd-srv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "lessThan": "5.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.252",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.202",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.165",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.128",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.75",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.16",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.6",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.252",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.202",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.165",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.128",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.75",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.16",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.6",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrnbd-srv: Zero the rsp buffer before using it\n\nBefore using the data buffer to send back the response message, zero it\ncompletely. This prevents any stray bytes to be picked up by the client\nside when there the message is exchanged between different protocol\nversions."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - RNBD server is reached over the RTRS RDMA network transport, which listens for remote RDMA clients and dispatches their RNBD protocol messages. The vulnerable responses are generated from network-originated session-info/open requests.\nAC:L - No race or fragile timing is required; an attacker only needs to establish a normal RTRS/RNBD session and send the relevant request. The vulnerable buffers are used deterministically in the response path.\nPR:N - RTRS connection setup checks protocol magic/version and session naming, but there is no authentication before RNBD_MSG_SESS_INFO is processed. The leak is reachable before any remote block device is successfully opened.\nUI:N - Exploitation does not require any victim action after the RNBD/RTRS server is loaded and listening. A remote peer can initiate the protocol exchange directly.\nS:U - The vulnerability discloses memory from the same kernel/server security authority that processes the RNBD request. It does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The server sends uninitialized bytes from unzeroed RTRS/RNBD response buffers back to the client in padding/reserved fields. Although each response is bounded, it is remotely repeatable across sessions and can expose stale kernel memory, so the higher confidentiality impact is chosen.\nI:N - The bug is an information disclosure caused by missing zero-initialization of response buffers. It does not provide a write primitive or alter server state beyond normal protocol behavior.\nA:N - The vulnerable path does not corrupt memory, panic, hang, or otherwise crash the server. It only leaks bytes in otherwise valid response messages."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:26:22.170Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e4272754063d52c9ad0169865add8816ba696471"
        },
        {
          "url": "https://git.kernel.org/stable/c/e2cacec7d4291300a282feb3af8eba57b93b15aa"
        },
        {
          "url": "https://git.kernel.org/stable/c/b646e54d23b9b592d612a2036aab14e0f6c14206"
        },
        {
          "url": "https://git.kernel.org/stable/c/30868a6a5238849d554295aff3ce61d242d7fad8"
        },
        {
          "url": "https://git.kernel.org/stable/c/7aac0a30dcf41cdb510526740d9a2ab1520c5d98"
        },
        {
          "url": "https://git.kernel.org/stable/c/c94ede3c436dfbd9cedd9cb69f604f6fc901b6a2"
        },
        {
          "url": "https://git.kernel.org/stable/c/852475278ca5e96e0c0275950e1a84203e602b33"
        },
        {
          "url": "https://git.kernel.org/stable/c/69d26698e4fd44935510553809007151b2fe4db5"
        }
      ],
      "title": "rnbd-srv: Zero the rsp buffer before using it",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43184",
    "datePublished": "2026-05-06T11:27:55.672Z",
    "dateReserved": "2026-05-01T14:12:55.991Z",
    "dateUpdated": "2026-08-05T12:26:22.170Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…