LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-68425

Published
CVSS7.1
Severityhigh
Weakness
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment. That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response

References

← Back to the CVE Tracker

Our coverage of CVE-2026-68425

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-68425.