CVE-2026-46145

Source
https://cve.org/CVERecord?id=CVE-2026-46145
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46145.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46145
Downstream
Related
Published
2026-05-28T09:36:01.805Z
Modified
2026-06-23T15:29:18.315776370Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/mana: Validate rx_hash_key_len
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana: Validate rxhashkey_len

Sashiko points out that rxhashkey_len comes from a uAPI structure and is blindly passed to memcpy, allowing the userspace to trash kernel memory. Bounds check it so the memcpy cannot overflow.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46145.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0266a177631d4c6b963b5b12dd986a8c5abdbf06
Fixed
7d7c9f0fcd19c4d2f0164347c58d49cafa961b72
Fixed
11c1431d641e0e4e0529e96957995820600c7287
Fixed
012796f9541fcd0c1fa8ae4da7eb4d83931ef838
Fixed
7d94f155f354b961c598f71bafa804dceded513f
Fixed
6dd2d4ad9c8429523b1c220c5132bd551c006425

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46145.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.88
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.30
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46145.json"