CVE-2026-92523
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute length RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are consumed directly with nla_get_u32(). The top-level policy validates only the container, so it does not establish the fixed shape of each child. Require every child payload to be exactly one u32 before reading it.
Is your site exposed to CVE-2026-92523?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0bfa897e3e1a61d172f95675b353168bc9290312
https://git.kernel.org/stable/c/74f49255492a62658f36bf2578d7916f1c6ffad1
https://git.kernel.org/stable/c/7828d68ae8cad3463e38def5c91668c84e722596
https://git.kernel.org/stable/c/c57e238b475e8e1e514499772b8c0db5768be93f
https://git.kernel.org/stable/c/d00b0d808ca706a04bd198827319a4a287eff82a
https://git.kernel.org/stable/c/f8e9315236c8b5155158c6955a758e7960b143e6
Frequently Asked Questions
What is CVE-2026-92523? +
In the Linux kernel, the following vulnerability has been resolved:
RDMA/nldev: validate dynamic counter attribute length
RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are
consumed directly with nla_get_u32(). The top-level policy validates only
the container, so it does not establish the fixed shape of each child.
Require every child payload to be exactly one u32 before reading it.
How do I check if I'm vulnerable to CVE-2026-92523? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.