PT-2026-98621 · Linux · Linux
CVE-2026-97957
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
CVSS v3.1
8.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
net: hinic: fix mailbox segment buffer overflow
check mbox seq id and seg len() validates that seq id does not
exceed SEQ ID MAX VAL (42) and seg len does not exceed
MBOX SEG LEN (48). However, this allows the last segment
(seq id=42) to carry a full 48-byte payload, writing to offset
42*48=2016 for 48 bytes (ending at byte 2064). The receive
buffer is only MBOX MAX BUF SZ (2048) bytes, resulting in a
16-byte heap buffer overflow.
The hinic3 driver already handles this correctly by defining
MBOX LAST SEG MAX LEN and rejecting the last segment when it
exceeds the remaining buffer space. Apply the same fix to the
hinic driver.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux