Out-of-bounds read in Linux kernel - CVE-2026-90416

 

Out-of-bounds read in Linux kernel - CVE-2026-90416

Published: September 18, 2026


Vulnerability identifier: #VU151063
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90416
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the get_param() function of the cc_params debugfs interface when reading a congestion parameter. A local user can read a crafted congestion parameter value through the debugfs interface to disclose sensitive information.

The issue is triggered when the parameter value has bit 31 set.


Affected software

Linux kernel

How to mitigate CVE-2026-90416

Install security update from vendor's repository.


External References

Related Security Bulletins