CVE-2026-93037

HIGHCVSS 7.8/10

Last modified

CVE-2026-93037 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the AHG change count, causing the caller to continue processing the request as though initialization had succeeded. Propagate sdma_txinit_ahg() failures to the caller and abort request processing when initialization fails. Found by Linux Verification Center (linuxtesting.org) with SVACE..

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the AHG change count, causing the caller to continue processing the request as though initialization had succeeded. Propagate sdma_txinit_ahg() failures to the caller and abort request processing when initialization fails. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < cb73c2fe6e9cf563c99f22b7c8bca0d5f70d603e; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < 122a730675565ff2ad210537c3fc3afb8291d482; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < bf974994150cfd14bfc599748925f4d426e00d90; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < fd6dee13f3857259b6b2ddd28e1ed95fd94ae2f9; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < 5b7cefffd15d87c8103865f887cdcf9077d8094b; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < 3416db552eb378e54cb2f2ce0db5f0df88654bda; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < ca99431820e8cac19f6a091c04da54cbe8d64f52; >= e3304b7cc4f14d365f46d6847a35563ae8b017f7, < 091c6162c022cbdfb64219708a71728cfd1d4600
LinuxLinux4.14

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-93037?
In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg(). If sdma_txinit_ahg() fails, it returns before initializing tx->txreq. However, set_txreq_header_ahg() ignores the error and returns the AHG change count, causing the caller to continue processing the request as though initialization had succeeded. Propagate sdma_txinit_ahg() failures to the caller and abort request processing when initialization fails. Found by Linux Verification Center (linuxtesting.org) with SVACE.
How severe is CVE-2026-93037?
CVE-2026-93037 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-93037?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-93037?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST