OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97421

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the RDMA/umem component, specifically in the ib_umem_find_best_pgsz() function, where improper handling of boundary conditions can lead to issues such as truncation of the I/O virtual address (iova) and potential overflow of the GENMASK for lengths exceeding 4GB. This could result in memory corruption or denial of service, particularly on 32-bit systems. Organizations utilizing Linux in environments with RDMA capabilities should prioritize addressing this vulnerability to mitigate potential risks.

CVE
CVE-2026-97421
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() Several corner cases, especially important on 32 bits: - umem->iova is u64, the function argument should pass in u64 or iova will be truncated - Check that the length is not too large for the iova - Check that lengths > 4G don't overflow the GENMASK