RDMA/mlx5: Fix integer overflow of user QP buffer size
Summary
| CVE | CVE-2026-90435 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:48 UTC |
| Updated | 2026-09-18 18:17:59 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer size set_user_buf_size() computes the QP buffer size by left-shifting the user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers. A sufficiently large rq.wqe_cnt causes signed integer overflow, which is undefined behavior, and yields a small or negative buf_size, causing ib_umem_get() to map a buffer smaller than the hardware will actually write into. Replace the shifts and addition with check_shl_overflow() and check_add_overflow(), rejecting invalid user inputs. Moreover, guard the identical shift computing qp->sq.offset in _create_user_qp() before set_user_buf_size() is reached. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001290000 probability, percentile 0.029060000 (date 2026-09-21)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c ccce6b7ef1d7efc59ccba3421e1339c6e63a3d20 git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c d99622e40aaa910ade681dfd4dc0fa240a011331 git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c c845e5e05140ea1bc64a5b1107942d93c876034d git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c 42fb8aefffff5b458aaa66803364a16e0ea44129 git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c d7fa2ff72ad1861eac194a4e0075d504ba8c246e git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c 5b6cfc6d7ff0959dd9766fdc24286a253b59ca77 git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c f917707f0de0832b8ab582391b1f64e549995c6c git | Not specified |
| CNA | Linux | Linux | affected e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c dec47e4b0fe34afdf38caa72b4408ba95502e5de git | Not specified |
| CNA | Linux | Linux | affected 3.11 | Not specified |
| CNA | Linux | Linux | unaffected 3.11 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/dec47e4b0fe34afdf38caa72b4408ba95502e5de | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5b6cfc6d7ff0959dd9766fdc24286a253b59ca77 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/42fb8aefffff5b458aaa66803364a16e0ea44129 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d99622e40aaa910ade681dfd4dc0fa240a011331 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c845e5e05140ea1bc64a5b1107942d93c876034d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d7fa2ff72ad1861eac194a4e0075d504ba8c246e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f917707f0de0832b8ab582391b1f64e549995c6c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ccce6b7ef1d7efc59ccba3421e1339c6e63a3d20 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.