CVE-2026-74346: RDMA/irdma: Fix OOB read during CQ MR registration
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix OOB read during CQ MR registration
Sashiko pointed out an unrelated bug during a previous patch: https://sashiko.dev/#/patchset/20260512183852.614045-1-jmoroni%40google.com
This change fixes the bug by eliminating the cqmr->split field which was not being set properly and instead just checks the CQ resize feature flag directly.
The cqmr->split field essentially tracks whether IRDMAFEATURECQRESIZE is set, but it was not being set until CQ creation time, which is after CQ memory registration (the only other place where it is referenced).
As a result, it would always be false during MR registration and would therefore cause irdmahandleqmem to populate cqmr->shadow even for GEN2 HW and beyond:
cqmr->shadow = (dmaaddrt)arr[req->cqpages];
The issue is that for GEN2 and beyond, req->cqpages may be exactly equal to iwmr->pagecnt and therefore equal to the size of arr, which would cause an OOB read by one.