PT-2026-98621 · Linux · Linux
CVE-2026-97957
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
net: hinic: fix mailbox segment buffer overflow
check mbox seq id and seg len() validates that seq id does not
exceed SEQ ID MAX VAL (42) and seg len does not exceed
MBOX SEG LEN (48). However, this allows the last segment
(seq id=42) to carry a full 48-byte payload, writing to offset
42*48=2016 for 48 bytes (ending at byte 2064). The receive
buffer is only MBOX MAX BUF SZ (2048) bytes, resulting in a
16-byte heap buffer overflow.
The hinic3 driver already handles this correctly by defining
MBOX LAST SEG MAX LEN and rejecting the last segment when it
exceeds the remaining buffer space. Apply the same fix to the
hinic driver.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux