Back

HIGH

cxl/features: Reject Get Feature count larger than the output buffer

Published Sep 17, 2026

Description

cxlctl_get_feature() sizes its output buffer from the user's fwctl_rpc.out_len, but the device is told to write cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a separate user-controlled value. Nothing bounds count against out_len, so a small out_len with a large count overflows the kvzalloc()'d buffer. A heap OOB write reachable from FWCTL_RPC.

Reject requests where count exceeds the available payload room, before allocating.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 17, 2026
Updated Sep 18, 2026
Reserved Sep 17, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a