Impact
A signed integer overflow occurs in the Linux kernel RDMA/mlx5 driver when calculating the queue pair buffer size: user‑supplied request‑queue entry counts and shift values are left‑shifted as signed integers; if the count is large enough the shift overflows, yielding a small or negative buffer size. The incomplete buffer mapping performed by ib_umem_get() allows the kernel to write beyond the mapped region, creating a window for memory corruption that could lead to privilege escalation.
Affected Systems
All Linux kernel releases that include the unpatched RDMA/mlx5 driver code, across all distributions that ship the patch‑unavailable kernel module, are affected. Any system that runs the mlx5 core module and exposes RDMA devices is potentially vulnerable until the fix is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Attackers would need local or privileged access to configure RDMA queue pairs with large entry counts, a capability normally restricted to users with RDMA device access or privileged processes; if such access is achieved, they could corrupt kernel memory. The patch mitigates the flaw by inserting overflow checks and rejecting unsafe parameters.
OpenCVE Enrichment
Debian DLA
Debian DSA