PT-2026-82161 · Linux · Linux Kernel
CVE-2026-80545
·
Published
2026-08-26
·
Updated
2026-08-28
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The
xcrb msg to type6 ep11cprb msgx() function fails to properly validate input, leading to several security issues. Specifically, the ep11 cprb structure and payload fields pld tag and pld lenfmt are copied from userspace without verifying if the buffer length is sufficient. Additionally, an arithmetic overflow can occur during CEIL4 alignment calculations, which may bypass size checks and enable buffer overflows. The function also incorrectly uses a simple C struct overlay to access fields of an ASN.1 encoded payload, where ASN.1 is a standard for defining data structures.Recommendations
Update the Linux kernel to a version where the
xcrb msg to type6 ep11cprb msgx() function has been patched to include size t for length calculations, U32 MAX boundary checks, and minimum request and reply size validation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel