PT-2026-52325 · Linux · Linux Kernel

CVE-2026-53230

·

Published

2026-06-25

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.0-rc6
Description A slab-out-of-bounds issue exists in the mlx5 query nic vport mac list() function. The function determines the size of the firmware command buffer based on the Physical Function (PF) log max current uc/mc list capabilities. If a Virtual Function (VF) vport is queried with a larger configured maximum via devlink, the firmware response can overflow the allocated buffer.
Recommendations Update the Linux kernel to version 7.0.0-rc6 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90882
CVE-2026-53230
ECHO-8B6A-5F3C-8FEC
OESA-2026-3204
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel