CVE-2026-53133 (GCVE-0-2026-53133)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the linearization of the mapping can give a single block that is very large split across multiple SG entries. When __rdma_block_iter_next() reassembles the split SG entries it is overflowing the 32 bit stack values and computed the wrong DMA addresses for blocks after the truncation. Use the right types to hold DMA addresses.
Impacted products
Vendor Product Version
Linux Linux Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Version: a808273a495c657e33281b181fd7fcc2bb28f662
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/core/iter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2ff4b7817e5b78070c30f5fb5e678e452a2628b3",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "dee2a49adeeb2a5e16a3fc858fa21b841c519802",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "cc644d5608e3b0dadc970bd6e6aa26b91ea07d0f",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "8fe0231adebe086c8a459c790944ac026cd99c6e",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "baf8685bcf56dc1efb44b8f6a57c42516e549068",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "afd35fec9297195b759078745549c2671223f24f",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "ac1aad8e1281534ce936c250f68084fc79c5469e",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            },
            {
              "lessThan": "15fe76e23615f502d051ef0768f86babaf08746c",
              "status": "affected",
              "version": "a808273a495c657e33281b181fd7fcc2bb28f662",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/core/iter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "lessThan": "5.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.94",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.36",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.259",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.94",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.36",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.13",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "5.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/umem: Fix truncation for block sizes \u003e= 4G\n\nWhen the iommu is used the linearization of the mapping can give a single\nblock that is very large split across multiple SG entries.\n\nWhen __rdma_block_iter_next() reassembles the split SG entries it is\noverflowing the 32 bit stack values and computed the wrong DMA addresses\nfor blocks after the truncation.\n\nUse the right types to hold DMA addresses."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Vulnerable code is reached through local RDMA uverbs operations such as opening `/dev/infiniband/uverbsX` and issuing memory-registration commands. Remote RDMA traffic may later exercise a bad MR, but the vulnerable iterator is invoked by local userspace registration, not by network packet parsing.\nAC:L - There is no race or probabilistic condition; on an affected RDMA/IOMMU deployment the attacker controls the MR address, length, and access flags needed to request large aligned mappings. Hardware/IOMMU support is an environmental prerequisite for the affected subsystem, not an exploitation step beyond attacker control.\nPR:L - The uverbs device node is created world-accessible and MR registration does not require CAP_SYS_ADMIN or CAP_NET_ADMIN, though the process must be an unprivileged local user able to use the RDMA device and pin memory under its memlock limits. No real init-namespace root privilege is required.\nUI:N - After local access to the RDMA device, the attacker can perform the open/context/PD/MR registration sequence directly. No separate victim action is required.\nS:U - The impact remains within the kernel/RDMA device memory-management security authority. This is not a guest-to-host escape, IOMMU boundary bypass by a guest, or another cross-scope boundary change.\nC:H - The truncation can program wrong DMA addresses into RDMA memory translation tables for blocks after the overflow. With RDMA read-capable access, the resulting mistranslation can expose unintended memory reachable through the device mapping, so the higher defensible confidentiality impact is High.\nI:H - The same wrong DMA translation can be used with local or remote write-capable MR permissions to direct RDMA writes to unintended mapped memory. Because this is device DMA memory corruption rather than a bounded metadata error, the higher defensible integrity impact is High.\nA:H - Incorrect DMA translations can cause IOMMU/device faults, corrupted RDMA state, or repeated failures of registered memory operations. Given the kernel/device-level DMA fault surface and the requirement to choose the higher severity when uncertain, availability impact is High."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:33:27.415Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2ff4b7817e5b78070c30f5fb5e678e452a2628b3"
        },
        {
          "url": "https://git.kernel.org/stable/c/dee2a49adeeb2a5e16a3fc858fa21b841c519802"
        },
        {
          "url": "https://git.kernel.org/stable/c/cc644d5608e3b0dadc970bd6e6aa26b91ea07d0f"
        },
        {
          "url": "https://git.kernel.org/stable/c/8fe0231adebe086c8a459c790944ac026cd99c6e"
        },
        {
          "url": "https://git.kernel.org/stable/c/baf8685bcf56dc1efb44b8f6a57c42516e549068"
        },
        {
          "url": "https://git.kernel.org/stable/c/afd35fec9297195b759078745549c2671223f24f"
        },
        {
          "url": "https://git.kernel.org/stable/c/ac1aad8e1281534ce936c250f68084fc79c5469e"
        },
        {
          "url": "https://git.kernel.org/stable/c/15fe76e23615f502d051ef0768f86babaf08746c"
        }
      ],
      "title": "RDMA/umem: Fix truncation for block sizes \u003e= 4G",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-53133",
    "datePublished": "2026-06-25T08:38:22.469Z",
    "dateReserved": "2026-06-09T07:44:35.386Z",
    "dateUpdated": "2026-08-05T12:33:27.415Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…