Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_ucaps() Sashiko pointed out it is not safe to rely only on the devt because char/block alias so if the user finds a block device with the same dev_t it can masquerade as a ucap cdev fd. Test the f_ops to only accept authentic cdevs.
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 61e51682816d395307f78ae06d640089054c28ab to <96b6e98ff12d50ed5817230c6f1188e1150d225d; 61e51682816d395307f78ae06d640089054c28ab to <aa181287ebdcc53ee0ba5c2f8243e2d541ebc19b; 61e51682816d395307f78ae06d640089054c28ab to <4a1b1ac2744694a2ecd66a84bdb1445f4ef24bee |
| Linux | Linux | 6.15; 0 to <6.15; 6.18.36 to <=6.18.*; 7.0.13 to <=7.0.*; 7.1 to <=* |
References
Generated from the official CVE List on 25 Jun 2026 10:14 UTC.