CVE-2026-63860

Source
https://cve.org/CVERecord?id=CVE-2026-63860
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63860.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63860
Downstream
Published
2026-07-19T14:04:48.153Z
Modified
2026-07-22T03:32:04.769831627Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/core: Prefer NLA_NUL_STRING
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Prefer NLANULSTRING

These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator.

Either this needs to switch to nlastrcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLANUL_STRING.

As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLANULSTRING use is the simpler solution.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63860.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
30dc5e63d6a5ad24894b5512d10b228d73645a44
Fixed
fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf
Fixed
87111356d58d86edb221ba144d261ed83a5b8bbe
Fixed
abda65bdd13084c771842adaac1f652d0660dd82
Fixed
137b5918931d4d05aa8ea8d3adf67f7224eef63c
Fixed
5877c043398d5fa0e93919a3d837e5cd7a98a961
Fixed
f2c7b39dde2e61df8157066969cc2a408cd3dcd9
Fixed
c26a0052cceed4c4d380ee5808b699f937fb58d8
Fixed
6ed3d14fc45d3da6025e7fe4a6a09066856698e2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63860.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.16.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63860.json"