Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs

get_param() reads a congestion parameter as a u32 but formats it with the
signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as
0x80000000, renders as "-2147483648\n" whose full length is 12. snprintf()
stores only 11 bytes yet returns 12, so simple_read_from_buffer() treats 12
bytes as valid and reads one byte past lbuf[].

Size the buffer for the widest unsigned decimal, format with "%u" to match
the u32, and use scnprintf() so the length passed to
simple_read_from_buffer() reflects the bytes actually stored.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The bug in the Linux kernel's mlx5 RDMA driver allows a stack out‑of‑bounds read in the cc_params debugfs interface. A user of the debugfs record can trigger get_param() to format a 32‑bit unsigned value with a signed specifier into an 11‑byte buffer. When the high bit is set, the formatted string is 12 bytes, causing simple_read_from_buffer() to read one byte past the end of the stack buffer. The leaked byte can expose kernel stack data, a sensitive secret, thereby violating confidentiality.

Affected Systems

Affected systems are Linux kernel builds that include the mlx5 RDMA driver and expose the cc_params debugfs entry. The exact kernel version list is not supplied, but any kernel with the exposed driver prior to the commit that fixed the bug is vulnerable.

Risk and Exploitability

The EPSS score indicates that exploitation probability is very low (<1%) and the vulnerability is not listed in CISA KEV. The attack vector is local, requiring read access to the debugfs file system, typically limited to privileged or local users. The lack of a CNA‑issued workaround suggests that the risk is mitigated by patching, although temporary mitigation can involve disabling or restricting debugfs access.

Generated by OpenCVE AI on September 19, 2026 at 13:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit that fixed the stack read bug.
  • If an immediate kernel update is unavailable, apply the patch manually by copying the relevant commit (03826bc1fa6c…) into the kernel source tree and rebuild.
  • Restrict access to the mlx5 cc_params debugfs file or unmount debugfs entirely to eliminate the read vector for untrusted users.

Generated by OpenCVE AI on September 19, 2026 at 13:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs get_param() reads a congestion parameter as a u32 but formats it with the signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as 0x80000000, renders as "-2147483648\n" whose full length is 12. snprintf() stores only 11 bytes yet returns 12, so simple_read_from_buffer() treats 12 bytes as valid and reads one byte past lbuf[]. Size the buffer for the widest unsigned decimal, format with "%u" to match the u32, and use scnprintf() so the length passed to simple_read_from_buffer() reflects the bytes actually stored.
Title RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:41.372Z

Reserved: 2026-09-11T19:38:34.813Z

Link: CVE-2026-90416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:45.880

Modified: 2026-09-17T17:17:45.880

Link: CVE-2026-90416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor