๐Ÿ” CVE Alert

CVE-2026-97957

UNKNOWN 0.0

net: hinic: fix mailbox segment buffer overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow check_mbox_seq_id_and_seg_len() validates that seq_id does not exceed SEQ_ID_MAX_VAL (42) and seg_len does not exceed MBOX_SEG_LEN (48). However, this allows the last segment (seq_id=42) to carry a full 48-byte payload, writing to offset 42*48=2016 for 48 bytes (ending at byte 2064). The receive buffer is only MBOX_MAX_BUF_SZ (2048) bytes, resulting in a 16-byte heap buffer overflow. The hinic3 driver already handles this correctly by defining MBOX_LAST_SEG_MAX_LEN and rejecting the last segment when it exceeds the remaining buffer space. Apply the same fix to the hinic driver.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c < eca54a092d5f7b497b458ff5a6f66d4f7bfb6674 a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c < 9f6ad383901d0cb1c8ea5f7f3160fabfe1540eb5 a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c < 513f7b16ed0cffae9348151c72bed17c7073096f a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c < 5d4d985957434867bbe85e4fa5e638f3e48ad522
Linux / Linux
5.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/eca54a092d5f7b497b458ff5a6f66d4f7bfb6674 git.kernel.org: https://git.kernel.org/stable/c/9f6ad383901d0cb1c8ea5f7f3160fabfe1540eb5 git.kernel.org: https://git.kernel.org/stable/c/513f7b16ed0cffae9348151c72bed17c7073096f git.kernel.org: https://git.kernel.org/stable/c/5d4d985957434867bbe85e4fa5e638f3e48ad522