« Volver al listado

CVE-2026-98025

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow

The 0xffff length sentinel detects a router reboot and schedules re-enabling of ethernet mode, but then falls through to the rest of the loop body. The next check is

which is the else of the just-matched if -- it never fires for len == 0xffff. The MTU bound that normally caps the incomplete-packet save path is silently bypassed.

With 0xffff > skb->len always true (rx_urb_size is 4096), the incomplete-packet branch saves dev->partial_len = skb->len bytes into dev->partial_data. partial_data is kmalloc(hard_mtu) = kmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the 2-byte header pull can be up to 4094.

Leer descripción completaMostrar menos

A device that sends a 4096-byte URB starting with [0xff 0xff] therefore copies 4094 device-provided bytes into a buffer allocated for 1516 bytes, exceeding its requested size by 2578 bytes.

The next URB then reads dev->partial_len (4094) back from the same 1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from the new URB's ~4KB skb, both well past their allocations, and delivers the spliced result as a 64KB "frame" to the network stack.

Bail out of rx_fixup after scheduling the re-enable work; the remainder of a reboot-marker URB is not meaningful packet data. This restores the invariant that partial_len < CX82310_MTU + 2 on the save path, since every other route there has already passed the MTU check.

Detalles técnicos trazas, registros y código del informe original
	} else if (len > CX82310_MTU) {

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98025",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "d0c1ce6ef4cefe568e19afa83f543caa3c3c0873",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "0dbc89e664b4609ad672b5bdeef60df251294b8f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "00520cdd21ea6a9b5dc8d53bbd241620d2059554",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "59bf9e94bdc49557f07d87164269daff7340f4d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "659654654eb140851467af41d610473c100c7975",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "237c9ae7145772af147e4665f158938350fa5658",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
              "lessThan": "5d50e90add8b4a978395e893e81954d19d58a7c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5adf7fbdfa3e9e425b04771e1d64c4e184ad8fdb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c1b187a86a176e42f5e48066556980e3232b6cab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.19.322",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.284",
              "lessThan": "5.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/net/usb/cx82310_eth.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/usb/cx82310_eth.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:31.110",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00520cdd21ea6a9b5dc8d53bbd241620d2059554",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0dbc89e664b4609ad672b5bdeef60df251294b8f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/237c9ae7145772af147e4665f158938350fa5658",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59bf9e94bdc49557f07d87164269daff7340f4d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5d50e90add8b4a978395e893e81954d19d58a7c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/659654654eb140851467af41d610473c100c7975",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0c1ce6ef4cefe568e19afa83f543caa3c3c0873",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow\n\nThe 0xffff length sentinel detects a router reboot and schedules\nre-enabling of ethernet mode, but then falls through to the rest\nof the loop body.  The next check is\n\n\t} else if (len > CX82310_MTU) {\n\nwhich is the else of the just-matched if -- it never fires for\nlen == 0xffff.  The MTU bound that normally caps the\nincomplete-packet save path is silently bypassed.\n\nWith 0xffff > skb->len always true (rx_urb_size is 4096), the\nincomplete-packet branch saves dev->partial_len = skb->len bytes\ninto dev->partial_data.  partial_data is kmalloc(hard_mtu) =\nkmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the\n2-byte header pull can be up to 4094.  A device that sends a\n4096-byte URB starting with [0xff 0xff] therefore copies 4094\ndevice-provided bytes into a buffer allocated for 1516 bytes,\nexceeding its requested size by 2578 bytes.\n\nThe next URB then reads dev->partial_len (4094) back from the same\n1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from\nthe new URB's ~4KB skb, both well past their allocations, and\ndelivers the spliced result as a 64KB \"frame\" to the network\nstack.\n\nBail out of rx_fixup after scheduling the re-enable work; the\nremainder of a reboot-marker URB is not meaningful packet data.\nThis restores the invariant that partial_len < CX82310_MTU + 2 on\nthe save path, since every other route there has already passed\nthe MTU check."
    }
  ],
  "lastModified": "2026-10-03T11:18:25.540",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}