Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap

bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap
flags, but a read-only mapping can still retain VM_MAYWRITE. nd later
be upgraded with mprotect(PROT_WRITE). This can bypass the write check
that only runs at mmap time.

Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page
branch, matching the existing policy that userspace writes are not
expected for these pages.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Write Access to Kernel Memory via RDMA
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel the bnxt_re RDMA driver incorrectly allows a read‑only memory mapping to be upgraded to writable through an mprotect call. The original mmap check rejects VM_WRITE for the database request buffer (DBR) and toggle page pages, yet a mapping can still retain the VM_MAYWRITE flag. If an attacker later performs an mprotect(PROT_WRITE), the kernel bypasses the write restriction that was only applied during mmap, enabling arbitrary writes to these kernel pages. The result is that an unauthorized user can modify critical kernel memory controlled by the RDMA subsystem, which could lead to privilege escalation or denial of service.

Affected Systems

This flaw affects any Linux system that uses the bnxt_re RDMA driver, typically the kernel itself across all distributions. No particular kernel versions are listed in the CNA data, so all current releases that include the driver are potentially impacted.

Risk and Exploitability

The EPSS score indicates less than one percent likelihood of exploitation at present and the issue is not present in the CISA KEV catalog, suggesting a low exploitation probability. The vulnerability is local to the RDMA device; an attacker would need write access to the device or privileged user rights adjacent to the vendor’s driver. The attack path does not require remote network access, but an untrusted user with kernel module privileges could exploit the flaw after the driver loads.

Generated by OpenCVE AI on September 19, 2026 at 06:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the bnxt_re_mmap patch that clears the VM_MAYWRITE flag before vm_insert_page.
  • If an update cannot be applied immediately, unload or disable the bnxt_re module on hosts where the RDMA device is not required.
  • Apply operating‑system access controls such as SELinux or AppArmor to restrict which users can invoke mprotect on kernel memory regions associated with the RDMA driver.
  • Monitor kernel logs for anomalous RDMA activity and treat any failures as potential exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-644
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap flags, but a read-only mapping can still retain VM_MAYWRITE. nd later be upgraded with mprotect(PROT_WRITE). This can bypass the write check that only runs at mmap time. Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page branch, matching the existing policy that userspace writes are not expected for these pages.
Title RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:10.747Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.670

Modified: 2026-09-17T17:17:51.670

Link: CVE-2026-92495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:45:14Z

Weaknesses
  • CWE-644

    Improper Neutralization of HTTP Headers for Scripting Syntax

  • CWE-787

    Out-of-bounds Write