PatchSiren cyber security CVE debrief
CVE-2026-46145 Linux CVE debrief
A missing bounds check in the Linux kernel's RDMA/mana driver allows userspace to specify an arbitrary rx_hash_key_len value, which is then passed directly to memcpy without validation. This can result in kernel memory corruption. The vulnerability has been resolved by adding proper validation of rx_hash_key_len before the memcpy operation.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-30
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-30
Who should care
System administrators running Linux kernels with MANA (Microsoft Azure Network Adapter) RDMA support enabled; cloud infrastructure operators using Azure VMs with RDMA capabilities; security teams monitoring kernel-level vulnerabilities affecting network drivers
Technical summary
The RDMA/mana driver in the Linux kernel failed to validate the rx_hash_key_len field from userspace uAPI structures before using it in a memcpy operation. This allowed malicious or malformed userspace input to trigger out-of-bounds memory writes in kernel space, potentially leading to memory corruption, crashes, or privilege escalation. The vulnerability was discovered by Sashiko and fixed by adding proper bounds validation before the memcpy call. The fix has been backported to multiple stable kernel branches as evidenced by five separate kernel.org stable commits.
Defensive priority
high
Recommended defensive actions
- Apply the relevant stable kernel patch for your kernel version
- Review systems using Microsoft Azure Network Adapter (MANA) RDMA functionality
- Monitor for kernel updates from your Linux distribution
- Verify kernel version includes the fix commit or its backport
Evidence notes
The CVE description and kernel commit references confirm this is a resolved vulnerability in the RDMA/mana driver. The fix adds bounds checking on rx_hash_key_len, which originates from a uAPI structure and was previously passed unchecked to memcpy. Multiple stable kernel commits are referenced, indicating backports to various kernel versions.
Official resources
-
CVE-2026-46145 CVE record
CVE.org
-
CVE-2026-46145 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
416baaa9-dc9f-4396-8d5f-8c081fb06d67
2026-05-28