{"schema_version":"1.7.5","id":"CVE-2026-23243","published":"2026-03-18T10:05:05.826Z","modified":"2026-07-16T03:31:11.604228814Z","related":["ALSA-2026:18134","ALSA-2026:18587","ALSA-2026:21706","ALSA-2026:21745","SUSE-SU-2026:1342-1","SUSE-SU-2026:1557-1","SUSE-SU-2026:1563-1","SUSE-SU-2026:1573-1","SUSE-SU-2026:1574-1","SUSE-SU-2026:1575-1","SUSE-SU-2026:1606-1","SUSE-SU-2026:1643-1","SUSE-SU-2026:1661-1","SUSE-SU-2026:1668-1","SUSE-SU-2026:1777-1","SUSE-SU-2026:21114-1","SUSE-SU-2026:21123-1","SUSE-SU-2026:21230-1","SUSE-SU-2026:21237-1","SUSE-SU-2026:21255-1","SUSE-SU-2026:2131-1","SUSE-SU-2026:2134-1","SUSE-SU-2026:21352-1","SUSE-SU-2026:21361-1","SUSE-SU-2026:2137-1","SUSE-SU-2026:2141-1","SUSE-SU-2026:2148-1","SUSE-SU-2026:2149-1","SUSE-SU-2026:2153-1","SUSE-SU-2026:2158-1","SUSE-SU-2026:2159-1","SUSE-SU-2026:2168-1","SUSE-SU-2026:2172-1","SUSE-SU-2026:2176-1","SUSE-SU-2026:2178-1","SUSE-SU-2026:2181-1","SUSE-SU-2026:21886-1","SUSE-SU-2026:21887-1","SUSE-SU-2026:21888-1","SUSE-SU-2026:21889-1","SUSE-SU-2026:2189-1","SUSE-SU-2026:21890-1","SUSE-SU-2026:21891-1","SUSE-SU-2026:21892-1","SUSE-SU-2026:21893-1","SUSE-SU-2026:21894-1","SUSE-SU-2026:21896-1","SUSE-SU-2026:21900-1","SUSE-SU-2026:21901-1","SUSE-SU-2026:21902-1","SUSE-SU-2026:21903-1","SUSE-SU-2026:21904-1","SUSE-SU-2026:21905-1","SUSE-SU-2026:21906-1","SUSE-SU-2026:21907-1","SUSE-SU-2026:21908-1","SUSE-SU-2026:21910-1","SUSE-SU-2026:21921-1","SUSE-SU-2026:21922-1","SUSE-SU-2026:21923-1","SUSE-SU-2026:21924-1","SUSE-SU-2026:21925-1","SUSE-SU-2026:21926-1","SUSE-SU-2026:21927-1","SUSE-SU-2026:21928-1","SUSE-SU-2026:21929-1","SUSE-SU-2026:21930-1","SUSE-SU-2026:21932-1","SUSE-SU-2026:21933-1","SUSE-SU-2026:21934-1","SUSE-SU-2026:21935-1","SUSE-SU-2026:21936-1","SUSE-SU-2026:21937-1","SUSE-SU-2026:21938-1","SUSE-SU-2026:21939-1","SUSE-SU-2026:21940-1","SUSE-SU-2026:21942-1","SUSE-SU-2026:21956-1","SUSE-SU-2026:21958-1","SUSE-SU-2026:21959-1","SUSE-SU-2026:21960-1","SUSE-SU-2026:21962-1","SUSE-SU-2026:21963-1","SUSE-SU-2026:21969-1","SUSE-SU-2026:21970-1","SUSE-SU-2026:21972-1","SUSE-SU-2026:21974-1","SUSE-SU-2026:21979-1","SUSE-SU-2026:21982-1","SUSE-SU-2026:21983-1","SUSE-SU-2026:2199-1","SUSE-SU-2026:22030-1","SUSE-SU-2026:22031-1","SUSE-SU-2026:22033-1","SUSE-SU-2026:22035-1","SUSE-SU-2026:22038-1","SUSE-SU-2026:22039-1","SUSE-SU-2026:22040-1","SUSE-SU-2026:22042-1","openSUSE-SU-2026:20572-1"],"summary":"RDMA/umad: Reject negative data_len in ib_umad_write","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/umad: Reject negative data_len in ib_umad_write\n\nib_umad_write computes data_len from user-controlled count and the\nMAD header sizes. With a mismatched user MAD header size and RMPP\nheader length, data_len can become negative and reach ib_create_send_mad().\nThis can make the padding calculation exceed the segment size and trigger\nan out-of-bounds memset in alloc_send_rmpp_list().\n\nAdd an explicit check to reject negative data_len before creating the\nsend buffer.\n\nKASAN splat:\n[  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0\n[  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102\n[  211.365867] ib_create_send_mad+0xa01/0x11b0\n[  211.365887] ib_umad_write+0x853/0x1c80","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"2be8e3ee8efd6f99ce454115c29d09750915021a"},{"fixed":"1371ef6b1ecf3676b8942f5dfb3634fb0648128e"},{"fixed":"362e45fd9069ffa1523f9f1633b606ebf72060d7"},{"fixed":"6eb2919474ca105c5b13d19574e25f0ddcf19ca2"},{"fixed":"a6a3e4af10993cb9e4b8f0548680aba0ab5f3b0d"},{"fixed":"9c80d688f402539dfc8f336de1380d6b4ee14316"},{"fixed":"205955f29c26330b1dc7fdeadd5bb97c38e26f56"},{"fixed":"52ab82cc5cf8ada5c3fb6ffe8f32fdb2fc27a34b"},{"fixed":"5551b02fdbfd85a325bb857f3a8f9c9f33397ed2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23243.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.24"},{"fixed":"5.10.252"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.202"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.165"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.128"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.75"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.14"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23243.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1371ef6b1ecf3676b8942f5dfb3634fb0648128e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/205955f29c26330b1dc7fdeadd5bb97c38e26f56"},{"type":"WEB","url":"https://git.kernel.org/stable/c/362e45fd9069ffa1523f9f1633b606ebf72060d7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/52ab82cc5cf8ada5c3fb6ffe8f32fdb2fc27a34b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5551b02fdbfd85a325bb857f3a8f9c9f33397ed2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6eb2919474ca105c5b13d19574e25f0ddcf19ca2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9c80d688f402539dfc8f336de1380d6b4ee14316"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a6a3e4af10993cb9e4b8f0548680aba0ab5f3b0d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23243.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23243"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23243.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}