CVE-2026-90416
CVE CVE-2026-90416EUVD EUVD-2026-82077Published 2026-09-17T16:09:41.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs get_param() reads a congestion parameter as a u32 but formats it with the signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as 0x80000000, renders as "-2147483648\n" whose full length is 12. snprintf() stores only 11 bytes yet returns 12, so simple_read_from_buffer() treats 12 bytes as valid and reads one byte past lbuf[]. Size the buffer for the widest unsigned decimal, format with "%u" to match the u32, and use scnprintf() so the length passed to simple_read_from_buffer() reflects the bytes actually stored.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <0b0122fcc923a0271130f5fb71af2cd7e20434d9; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <c75ee076fa09778a2f9602a972dade4a0b0785f7; patch: 5.15.221; patch: 0; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <1c5b4f76cd73372c5a8a4c91c95d5a31f141e091; patch: 6.12.110; patch: 6.6.157; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <06b62758f81e27ca4c81201c22e3436c6d9ac894; 4.14; patch: 7.2.6; patch: 5.10.270; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <ce8dfd32a33b578c3abf178f67b4c8d36854f041; patch: 6.18.52; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <03826bc1fa6c90405bf05831f2b501a8368dcd27; patch: 7.3-rc1; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <4599311e78e88c893ad551aca622de2bfdf1c31f; patch: 6.1.188; 4a2da0b8c0782816f3ae6846ae7942fcbb0f8172 <d809cf3f0ed9255abfc73c4730bcf187151422af
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.