Out-of-Bounds Read in Linux Kernel's mlx5 Module
CVE-2026-74712

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74712?

A vulnerability in the Linux kernel's mlx5 module allows for an out-of-bounds read due to improper input size calculations during command execution. This flaw occurs when the 'create_direct_keys' function fails to account for the total size required for both input and output buffers, causing memory operations to exceed allocated boundaries. This bug may lead to unexpected behavior or exploitation in virtualized environments relying on the mlx5 driver. Mitigation involves properly calculating buffer sizes to align with the expectations of the command execution functionality.

Affected Version(s)

Linux 0071b138d44af4296bf871e6624369ce697b4b15

Linux 0071b138d44af4296bf871e6624369ce697b4b15

Linux 0071b138d44af4296bf871e6624369ce697b4b15 < 6c8a9f7bc00301e533a5366384f3070a8e7f8430

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.