PT-2026-98621 · Linux · Linux

CVE-2026-97957

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
net: hinic: fix mailbox segment buffer overflow
check mbox seq id and seg len() validates that seq id does not exceed SEQ ID MAX VAL (42) and seg len does not exceed MBOX SEG LEN (48). However, this allows the last segment (seq id=42) to carry a full 48-byte payload, writing to offset 42*48=2016 for 48 bytes (ending at byte 2064). The receive buffer is only MBOX MAX BUF SZ (2048) bytes, resulting in a 16-byte heap buffer overflow.
The hinic3 driver already handles this correctly by defining MBOX LAST SEG MAX LEN and rejecting the last segment when it exceeds the remaining buffer space. Apply the same fix to the hinic driver.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97957

Produtos afetados

Linux