{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74712","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.928Z","datePublished":"2026-08-22T15:33:08.392Z","dateUpdated":"2026-08-25T05:41:54.897Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-25T05:41:54.897Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/mlx5: Fix buffer length in create_direct_keys()\n\nWe have seen in our CI the following KASAN message:\nBUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core]\nRead of size 272 at addr 0000000176795020 by task qemu-system-s39/82764\n[...]\n[<000011388ab3a7a0>] cmd_exec+0x550/0xca0 [mlx5_core]\n[<000011388ab3b61c>] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core]\n[<000011388b21e82e>] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa]\n[<000011388b21fd44>] create_direct_keys+0x954/0xef0 [mlx5_vdpa]\n[...]\nThe buggy address is located 4128 bytes inside of\nallocated 4384-byte region [0000000176794000, 0000000176795120)\n\nSo in essence we read 16 bytes beyond 4384-byte allocation.\ncreate_direct_keys calculates the pointer and length for in and out\nbuffers.\nThe size calculation for in includes the entire structure\nsize (out + in + mtt[]) but the pointer passed to cmd_exec points only\nto the 'in' field, skipping the 'out' field.\n\nThis causes mlx5_copy_to_msg() to read beyond the allocated buffer\nby sizeof(out) bytes when copying command data.\n\nProperly calculate the input size to match the pointer and allocation size."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached when host vDPA memory keys are created during IOTLB/set_map handling on /dev/vhost-vdpa (ioctl/write from QEMU/vhost), not from remote network packet processing; worst case is a co-tenant VM guest driving host QEMU virtio memory updates on the same mlx5 vDPA host.\nAC:L - Once mlx5 vDPA user MR setup runs, create_direct_keys() always passes an oversized inlen to mlx5_cmd_exec_cb(), deterministically causing mlx5_copy_to_msg() to read past the slab allocation; no race or victim state is required beyond normal virtio memory mapping.\nPR:N - In cloud mlx5 virtio-vDPA deployments a malicious VM tenant needs no host credentials—normal guest virtio-net bring-up causes QEMU to issue vhost IOTLB updates that invoke mlx5_vdpa_set_map() and create_user_mr() on the host without CAP_NET_ADMIN or root in the host init namespace.\nUI:N - Exploitation requires only automated virtio driver initialization and memory table updates; no additional victim clicks, mounts, or manual actions are needed beyond provisioning a vDPA-backed VM, which is the intended operational path.\nS:C - The vulnerable mlx5 vDPA code runs in the hypervisor host kernel while the practical attacker is a guest VM tenant; successful slab out-of-bounds reads and corrupted firmware commands cross the guest/host virtualization boundary per KVM guest-to-host guidance.\nC:H - Incorrect inlen makes mlx5_copy_to_msg() perform a slab out-of-bounds read (KASAN-reported) of adjacent kernel heap memory, copying leaked bytes into CREATE_MKEY commands and enabling arbitrary kernel information disclosure, not a bounded benign leak.\nI:H - The over-read injects adjacent heap contents into firmware CREATE_MKEY command buffers, corrupting memory-key setup data sent to the mlx5 device; this is exploitable kernel memory corruption that can alter device DMA mappings and enable further control, not a read-only crash.\nA:H - The flaw triggers a KASAN slab-out-of-bounds fault in mlx5_core cmd_exec() during normal MR creation; such heap corruption commonly causes kernel oops/panic and can also destabilize vDPA networking on repeated virtio memory remaps."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vdpa/mlx5/core/mr.c"],"versions":[{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"ec3bb289cf19d526224117d5d450a5fd9cbd5ab2","status":"affected","versionType":"git"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"cde8931a25392670dd59a0acfcab87a830ab66c5","status":"affected","versionType":"git"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"6c8a9f7bc00301e533a5366384f3070a8e7f8430","status":"affected","versionType":"git"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"727e1f569855df83579edbd73dcb4a0723543a12","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vdpa/mlx5/core/mr.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.12.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.18.45"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ec3bb289cf19d526224117d5d450a5fd9cbd5ab2"},{"url":"https://git.kernel.org/stable/c/cde8931a25392670dd59a0acfcab87a830ab66c5"},{"url":"https://git.kernel.org/stable/c/6c8a9f7bc00301e533a5366384f3070a8e7f8430"},{"url":"https://git.kernel.org/stable/c/727e1f569855df83579edbd73dcb4a0723543a12"}],"title":"vdpa/mlx5: Fix buffer length in create_direct_keys()","x_generator":{"engine":"bippy-1.2.0"}}}}