Out-of-Bounds Read in Linux Kernel's mlx5 Module
CVE-2026-74712
What is CVE-2026-74712?
A vulnerability in the Linux kernel's mlx5 module allows for an out-of-bounds read due to improper input size calculations during command execution. This flaw occurs when the 'create_direct_keys' function fails to account for the total size required for both input and output buffers, causing memory operations to exceed allocated boundaries. This bug may lead to unexpected behavior or exploitation in virtualized environments relying on the mlx5 driver. Mitigation involves properly calculating buffer sizes to align with the expectations of the command execution functionality.
Affected Version(s)
Linux 0071b138d44af4296bf871e6624369ce697b4b15
Linux 0071b138d44af4296bf871e6624369ce697b4b15
Linux 0071b138d44af4296bf871e6624369ce697b4b15 < 6c8a9f7bc00301e533a5366384f3070a8e7f8430