Review reviewHigh

CVE-2026-63860

Linux

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.

CVSS
8.4
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.4

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.

Affected product and versions

Product
Linux
Affected versions
>= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < 87111356d58d86edb221ba144d261ed83a5b8bbe, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < abda65bdd13084c771842adaac1f652d0660dd82, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < 137b5918931d4d05aa8ea8d3adf67f7224eef63c, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < 5877c043398d5fa0e93919a3d837e5cd7a98a961, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < f2c7b39dde2e61df8157066969cc2a408cd3dcd9, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < c26a0052cceed4c4d380ee5808b699f937fb58d8, >= 30dc5e63d6a5ad24894b5512d10b228d73645a44 < 6ed3d14fc45d3da6025e7fe4a6a09066856698e2, >= 3.16
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available