Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90416— RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux 内核中已修复了以下漏洞: RDMA/mlx5:修复 cc_params debugfs 中的栈越界读取 函数以 u32 类型读取拥塞控制参数,但使用有符号格式说明符 将其格式化输出到一个 11 字节的栈缓冲区中。如果参数值的第 31 位为 1(例如 ),格式化后的字符串为 ,总长度为 12 字节。 实际只存储了 11 个字节,但返回值为 12,导致 误认为有 12 字节有效数据,从而读取了 缓冲区末尾之外一个字节的位置。 修复方案: 1. 将缓冲区大小调整为能容纳最宽 unsigned 十进制数的长度;

AI Predicted 3.1 Difficulty: Hard EPSS 0.22% · P11

Possible ATT&CK Techniques 1 AI

T1069 · Permission Groups Discovery

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< 1c5b4f76cd73372c5a8a4c91c95d5a31f141e091 affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< 06b62758f81e27ca4c81201c22e3436c6d9ac894 affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< d809cf3f0ed9255abfc73c4730bcf187151422af affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< 0b0122fcc923a0271130f5fb71af2cd7e20434d9 affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< ce8dfd32a33b578c3abf178f67b4c8d36854f041 affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< 4599311e78e88c893ad551aca622de2bfdf1c31f affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< c75ee076fa09778a2f9602a972dade4a0b0785f7 affected
4a2da0b8c0782816f3ae6846ae7942fcbb0f8172< 03826bc1fa6c90405bf05831f2b501a8368dcd27 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90416

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs get_param() reads a congestion parameter as a u32 but formats it with the signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as 0x80000000, renders as "-2147483648\n" whose full length is 12. snprintf() stores only 11 bytes yet returns 12, so simple_read_from_buffer() treats 12 bytes as valid and reads one byte past lbuf[]. Size the buffer for the widest unsigned decimal, format with "%u" to match the u32, and use scnprintf() so the length passed to simple_read_from_buffer() reflects the bytes actually stored.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 ~ 1c5b4f76cd73372c5a8a4c91c95d5a31f141e091 -
Linux Linux 4.14 -

II. Public POCs for CVE-2026-90416

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90416

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-90416 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90240 8.8 HIGH iommu/vt-d: Flush context cache with correct SID when tearing down aliases
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90286 8.8 HIGH drm/amdgpu/gfx6: Use PFP on the compute queues too
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-90416

No comments yet


Leave a comment