AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-68419

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's RDMA/irdma component, where user applications can invoke the rereg_mr operation on special memory regions, potentially leading to the emission of a command with an uninitialized memory key (mkey). This could allow unauthorized access or manipulation of memory regions, posing a risk to system integrity and security. Organizations using Linux systems with RDMA capabilities should prioritize this issue to mitigate potential exploitation risks.

CVE
CVE-2026-68419
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a two step process is used where the buffer is allocated in userspace and explicitly registered with the normal reg_mr mechanism prior to creating the actual QP/CQ/SRQ object. These special registrations are indicated via an ABI field so the driver knows that they do not have a valid mkey and to skip the actual CQP command submission. Since these are real MR objects from the core's perspective, it is possible for a user application to invoke rereg_mr on them and cause a real CQP op to be emitted with the zero-initialized mkey value of 0. Fix this by preventing rereg_mr on these special regions.