CVE-2026-90307 | Linux Kernel up to 7.2.5 RDMA/SRP srp_recv_done byte_len out-of-bounds
A vulnerability was found in Linux Kernel up to 7.2.5. It has been rated as problematic. Affected by this issue is the function srp_recv_done of the component RDMA/SRP. The manipulation of the argument byte_len leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-90307. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.