GHSA-cm7q-3wq8-gx9wunknown

In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic...

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

RDMA/nldev: validate dynamic counter attribute length

RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are consumed directly with nla_get_u32(). The top-level policy validates only the container, so it does not establish the fixed shape of each child.

Require every child payload to be exactly one u32 before reading it.

🔗 References (8)