Database/Kernel, userspace & hypervisor
Linux kernel mlx5_ib (queue pair sizing): set_rq_size() computes the receive-queue work-entry size as 1 << rq_wqe_shift
Impact
set_rq_size() computes the receive-queue work-entry size as 1 << rq_wqe_shift from a user-supplied shift that is only checked against being greater than 32, so shifts of 31 and 32 pass and overflow. A tenant process controls a shift that the kernel then uses to size an allocation - the classic setup for heap corruption from an RDMA verbs call.
Who can reach it
Local, low-privileged - any process that can create an RDMA queue pair on an mlx5 device.
What to do
Upgrade the host kernel to 7.2 or a stable backport (5.10.261, 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5). Rolling reboot across the RDMA fleet.
References
Related entries
- Linux kernel (drivers/vfio/pci/qat): Two concurrent writes to the QAT VF migration-resume file both pass the boundsCVE-2026-74306 · Linux kernel (drivers/vfio/pci/qat)High
- Linux kernel BPF: BPF_PROG_QUERY writes the revision field past a short bpf_attr from userspaceCVE-2026-74371 · Linux kernel BPF BPF_PROG_QUERY (cgroup query revision write-back)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2026-74446 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-74447 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel THP split: use-after-free on the inode when memory-failure splits a shmem huge pageCVE-2026-74482 · Linux kernel mm/huge_memory (__folio_split i_mmap_rwsem release order)High
- Linux kernel hugetlbfs: list corruption in reservation top-up can link a kernel-stack address into MM stateCVE-2026-74518 · Linux kernel hugetlbfs reservation map (allocate_file_region_entries)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.