0.0
NA
CVE-2026-63860
RDMA/core: Prefer NLA_NUL_STRING
Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.

INFO

Published Date :

July 19, 2026, 3:16 p.m.

Last Modified :

July 19, 2026, 3:16 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-63860 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Update the Linux kernel to resolve the attribute evaluation issue.
  • Update the Linux kernel.
  • Use NLA_NUL_STRING for attribute evaluation.
  • Adjust printf fmt specifier for %s.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-63860 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-63860 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-63860 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-63860 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 19, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': 'fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': '87111356d58d86edb221ba144d261ed83a5b8bbe', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': 'abda65bdd13084c771842adaac1f652d0660dd82', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': '137b5918931d4d05aa8ea8d3adf67f7224eef63c', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': '5877c043398d5fa0e93919a3d837e5cd7a98a961', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': 'f2c7b39dde2e61df8157066969cc2a408cd3dcd9', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': 'c26a0052cceed4c4d380ee5808b699f937fb58d8', 'versionType': 'git'}, {'status': 'affected', 'version': '30dc5e63d6a5ad24894b5512d10b228d73645a44', 'lessThan': '6ed3d14fc45d3da6025e7fe4a6a09066856698e2', 'versionType': 'git'}], 'programFiles': ['drivers/infiniband/core/iwpm_msg.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.16'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.16', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.258', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/infiniband/core/iwpm_msg.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.
    Added Reference https://git.kernel.org/stable/c/137b5918931d4d05aa8ea8d3adf67f7224eef63c
    Added Reference https://git.kernel.org/stable/c/5877c043398d5fa0e93919a3d837e5cd7a98a961
    Added Reference https://git.kernel.org/stable/c/6ed3d14fc45d3da6025e7fe4a6a09066856698e2
    Added Reference https://git.kernel.org/stable/c/87111356d58d86edb221ba144d261ed83a5b8bbe
    Added Reference https://git.kernel.org/stable/c/abda65bdd13084c771842adaac1f652d0660dd82
    Added Reference https://git.kernel.org/stable/c/c26a0052cceed4c4d380ee5808b699f937fb58d8
    Added Reference https://git.kernel.org/stable/c/f2c7b39dde2e61df8157066969cc2a408cd3dcd9
    Added Reference https://git.kernel.org/stable/c/fcd07d3b8ee7a39b344d73aed69c1a68cd9eacdf
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.