PT-2026-94764 · Linux · Linux Kernel

CVE-2026-90416

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stack out-of-bounds read exists in the RDMA/mlx5 cc params debugfs. The get param() function reads a congestion parameter as a u32 but formats it using a signed %d into an 11-byte stack buffer. If a value has bit 31 set, the resulting string can reach 12 characters. Because snprintf() stores only 11 bytes but returns 12, the simple read from buffer() function reads one byte beyond the lbuf[] buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103044
CVE-2026-90416
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel