Boletines de Vulnerabilidades

CVE-2026-45962

   
Software afectado LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

ublk: Validate SQE128 flag before accessing the cmd

ublk_ctrl_cmd_dump() accesses (header *)sqe->cmd before
IO_URING_F_SQE128 flag check. This could cause out of boundary memory
access.

Move the SQE128 flag check earlier in ublk_ctrl_uring_cmd() to return
-EINVAL immediately if the flag is not set.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-45962