SB2026011462 - Input validation error in Linux kernel core diag driver
Published: January 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-68816)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.h. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/38ac688b52ef26a88f8bc4fe26d24fdd0ff91e5d
- https://git.kernel.org/stable/c/45bd283b1d69e2c97cddcb9956f0e0261fc4efd7
- https://git.kernel.org/stable/c/8ac688c0e430dab19f6a9b70df94b1f635612c1a
- https://git.kernel.org/stable/c/8c35c2448086870509ede43947845be0833251f0
- https://git.kernel.org/stable/c/b35966042d20b14e2d83330049f77deec5229749