Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Fix integer overflow of user QP buffer size

set_user_buf_size() computes the QP buffer size by left-shifting the
user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers.
A sufficiently large rq.wqe_cnt causes signed integer overflow, which
is undefined behavior, and yields a small or negative buf_size, causing
ib_umem_get() to map a buffer smaller than the hardware will actually
write into.

Replace the shifts and addition with check_shl_overflow() and
check_add_overflow(), rejecting invalid user inputs.

Moreover, guard the identical shift computing qp->sq.offset in
_create_user_qp() before set_user_buf_size() is reached.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel memory corruption via RDMA queue pair buffer miscalculation
Action: Patch Now
AI Analysis

Impact

A signed integer overflow occurs in the Linux kernel RDMA/mlx5 driver when calculating the queue pair buffer size: user‑supplied request‑queue entry counts and shift values are left‑shifted as signed integers; if the count is large enough the shift overflows, yielding a small or negative buffer size. The incomplete buffer mapping performed by ib_umem_get() allows the kernel to write beyond the mapped region, creating a window for memory corruption that could lead to privilege escalation.

Affected Systems

All Linux kernel releases that include the unpatched RDMA/mlx5 driver code, across all distributions that ship the patch‑unavailable kernel module, are affected. Any system that runs the mlx5 core module and exposes RDMA devices is potentially vulnerable until the fix is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies this as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Attackers would need local or privileged access to configure RDMA queue pairs with large entry counts, a capability normally restricted to users with RDMA device access or privileged processes; if such access is achieved, they could corrupt kernel memory. The patch mitigates the flaw by inserting overflow checks and rejecting unsafe parameters.

Generated by OpenCVE AI on September 20, 2026 at 01:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that contains the RDMA/mlx5 integer overflow fix.
  • If RDMA is unnecessary, disable RDMA services and unload the mlx5_core module to eliminate the vulnerable code path.
  • Restrict RDMA device access by applying appropriate permission settings or device access controls, ensuring only trusted users or privileged processes can create RDMA queue pairs.

Generated by OpenCVE AI on September 20, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-680

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Sat, 19 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer size set_user_buf_size() computes the QP buffer size by left-shifting the user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers. A sufficiently large rq.wqe_cnt causes signed integer overflow, which is undefined behavior, and yields a small or negative buf_size, causing ib_umem_get() to map a buffer smaller than the hardware will actually write into. Replace the shifts and addition with check_shl_overflow() and check_add_overflow(), rejecting invalid user inputs. Moreover, guard the identical shift computing qp->sq.offset in _create_user_qp() before set_user_buf_size() is reached.
Title RDMA/mlx5: Fix integer overflow of user QP buffer size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:24.102Z

Reserved: 2026-09-11T19:38:34.815Z

Link: CVE-2026-90435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:48.770

Modified: 2026-09-18T18:17:59.280

Link: CVE-2026-90435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-680

    Integer Overflow to Buffer Overflow