Impact
The bug in the Linux kernel's mlx5 RDMA driver allows a stack out‑of‑bounds read in the cc_params debugfs interface. A user of the debugfs record can trigger get_param() to format a 32‑bit unsigned value with a signed specifier into an 11‑byte buffer. When the high bit is set, the formatted string is 12 bytes, causing simple_read_from_buffer() to read one byte past the end of the stack buffer. The leaked byte can expose kernel stack data, a sensitive secret, thereby violating confidentiality.
Affected Systems
Affected systems are Linux kernel builds that include the mlx5 RDMA driver and expose the cc_params debugfs entry. The exact kernel version list is not supplied, but any kernel with the exposed driver prior to the commit that fixed the bug is vulnerable.
Risk and Exploitability
The EPSS score indicates that exploitation probability is very low (<1%) and the vulnerability is not listed in CISA KEV. The attack vector is local, requiring read access to the debugfs file system, typically limited to privileged or local users. The lack of a CNA‑issued workaround suggests that the risk is mitigated by patching, although temporary mitigation can involve disabling or restricting debugfs access.
OpenCVE Enrichment
Debian DLA
Debian DSA