PT-2026-72218 · Linux · Linux Kernel
CVE-2026-72029
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the MUX downlink decoder of the iosm net device. The
mux dl adb decode() function processes a chain of aggregated datagram tables using offsets and lengths provided by the modem, specifically first table index, next table index, table length, datagram index, and datagram length. Because these values are not properly validated against the received socket buffer (skb), a modem providing indices or lengths beyond the downlink buffer can cause an out-of-bounds read. Additionally, the lack of a forward progress check when following the table chain allows a modem to create circular references between tables, leading to an infinite loop that runs in softirq and continuously clones the skb.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel