PT-2026-82161 · Linux · Linux Kernel

CVE-2026-80545

·

Published

2026-08-26

·

Updated

2026-08-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The xcrb msg to type6 ep11cprb msgx() function fails to properly validate input, leading to several security issues. Specifically, the ep11 cprb structure and payload fields pld tag and pld lenfmt are copied from userspace without verifying if the buffer length is sufficient. Additionally, an arithmetic overflow can occur during CEIL4 alignment calculations, which may bypass size checks and enable buffer overflows. The function also incorrectly uses a simple C struct overlay to access fields of an ASN.1 encoded payload, where ASN.1 is a standard for defining data structures.
Recommendations Update the Linux kernel to a version where the xcrb msg to type6 ep11cprb msgx() function has been patched to include size t for length calculations, U32 MAX boundary checks, and minimum request and reply size validation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80545

Affected Products

Linux Kernel