Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/nldev: validate dynamic counter attribute length

RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are
consumed directly with nla_get_u32(). The top-level policy validates only
the container, so it does not establish the fixed shape of each child.

Require every child payload to be exactly one u32 before reading it.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel out‑of‑bounds read potentially leading to crash or privilege escalation
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s RDMA/nldev netlink interface the nested attribute RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is erroneously allowed to have children of arbitrary length because the top‑level policy only checks the container size. The code proceeds to call nla_get_u32 on each child without validating that the payload is exactly one 32‑bit integer. Based on the description, it is inferred that this can trigger an out‑of‑bounds read and may cause a kernel fault, which in turn could be escalated to arbitrary code execution. The underlying weakness is improper bounds checking.

Affected Systems

The flaw resides in the Linux kernel itself and therefore applies to all distributions that ship an unmodified kernel containing the buggy RDMA/nldev code. No specific product version list is provided, so any kernel build without the patch is affected. The issue affects every architecture supported by the kernel because it lies in generic netlink parsing code used by RDMA interfaces.

Risk and Exploitability

The EPSS score for this vulnerability is less than 1%, indicating very low exploitation probability in the wild. It is not listed in the CISA KEV catalog. Although the CVSS severity is not given explicitly, the potential for kernel crash or privilege escalation classifies the risk as high. Based on the description, it is inferred that the likely attack vector involves an attacker who can send crafted netlink messages to the kernel, such as a local privileged user or an application that interfaces with RDMA. If the attacker can target the RDMA netlink socket, they can exploit the out‑of‑bounds read to destabilize the system or potentially execute code with kernel privileges. Therefore, applying the proper kernel patch is required to mitigate the risk.

Generated by OpenCVE AI on September 19, 2026 at 09:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the RDMA/nldev attribute length validation fix
  • If a kernel upgrade is not immediately possible, restrict local users’ ability to access the RDMA netlink socket, for example by removing CAP_NET_ADMIN or adopting network‑namespace isolation
  • As a temporary workaround, implement a patch that verifies each RDMA_NLDEV_ATTR_STAT_HWCOUNTERS child payload is exactly one u32 before nla_get_u32 is called

Generated by OpenCVE AI on September 19, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-129

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are consumed directly with nla_get_u32(). The top-level policy validates only the container, so it does not establish the fixed shape of each child. Require every child payload to be exactly one u32 before reading it.
Title RDMA/nldev: validate dynamic counter attribute length
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:29.474Z

Reserved: 2026-09-16T12:21:13.874Z

Link: CVE-2026-92523

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:55.283

Modified: 2026-09-17T17:17:55.283

Link: CVE-2026-92523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:00:08Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-129

    Improper Validation of Array Index