PT-2026-94764 · Linux · Linux Kernel
CVE-2026-90416
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A stack out-of-bounds read exists in the RDMA/mlx5
cc params debugfs. The get param() function reads a congestion parameter as a u32 but formats it using a signed %d into an 11-byte stack buffer. If a value has bit 31 set, the resulting string can reach 12 characters. Because snprintf() stores only 11 bytes but returns 12, the simple read from buffer() function reads one byte beyond the lbuf[] buffer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel