CVE-2026-98025
In the Linux kernel, the following vulnerability has been resolved:
net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow
The 0xffff length sentinel detects a router reboot and schedules re-enabling of ethernet mode, but then falls through to the rest of the loop body. The next check is
which is the else of the just-matched if -- it never fires for len == 0xffff. The MTU bound that normally caps the incomplete-packet save path is silently bypassed.
With 0xffff > skb->len always true (rx_urb_size is 4096), the incomplete-packet branch saves dev->partial_len = skb->len bytes into dev->partial_data. partial_data is kmalloc(hard_mtu) = kmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the 2-byte header pull can be up to 4094.
Leer descripción completaMostrar menos
A device that sends a 4096-byte URB starting with [0xff 0xff] therefore copies 4094 device-provided bytes into a buffer allocated for 1516 bytes, exceeding its requested size by 2578 bytes.
The next URB then reads dev->partial_len (4094) back from the same 1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from the new URB's ~4KB skb, both well past their allocations, and delivers the spliced result as a 64KB "frame" to the network stack.
Bail out of rx_fixup after scheduling the re-enable work; the remainder of a reboot-marker URB is not meaningful packet data. This restores the invariant that partial_len < CX82310_MTU + 2 on the save path, since every other route there has already passed the MTU check.
Detalles técnicos trazas, registros y código del informe original
} else if (len > CX82310_MTU) {CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/00520cdd21ea6a9b5dc8d53bbd241620d2059554
- https://git.kernel.org/stable/c/0dbc89e664b4609ad672b5bdeef60df251294b8f
- https://git.kernel.org/stable/c/237c9ae7145772af147e4665f158938350fa5658
- https://git.kernel.org/stable/c/3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287
- https://git.kernel.org/stable/c/59bf9e94bdc49557f07d87164269daff7340f4d6
- https://git.kernel.org/stable/c/5d50e90add8b4a978395e893e81954d19d58a7c5
- https://git.kernel.org/stable/c/659654654eb140851467af41d610473c100c7975
- https://git.kernel.org/stable/c/d0c1ce6ef4cefe568e19afa83f543caa3c3c0873
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98025",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "d0c1ce6ef4cefe568e19afa83f543caa3c3c0873",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "0dbc89e664b4609ad672b5bdeef60df251294b8f",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "00520cdd21ea6a9b5dc8d53bbd241620d2059554",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "59bf9e94bdc49557f07d87164269daff7340f4d6",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "659654654eb140851467af41d610473c100c7975",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "237c9ae7145772af147e4665f158938350fa5658",
"versionType": "git"
},
{
"status": "affected",
"version": "ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808",
"lessThan": "5d50e90add8b4a978395e893e81954d19d58a7c5",
"versionType": "git"
},
{
"status": "affected",
"version": "5adf7fbdfa3e9e425b04771e1d64c4e184ad8fdb",
"versionType": "git"
},
{
"status": "affected",
"version": "c1b187a86a176e42f5e48066556980e3232b6cab",
"versionType": "git"
},
{
"status": "affected",
"version": "4.19.322",
"lessThan": "4.20",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.284",
"lessThan": "5.5",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/usb/cx82310_eth.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/usb/cx82310_eth.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:31.110",
"references": [
{
"url": "https://git.kernel.org/stable/c/00520cdd21ea6a9b5dc8d53bbd241620d2059554",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0dbc89e664b4609ad672b5bdeef60df251294b8f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/237c9ae7145772af147e4665f158938350fa5658",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/59bf9e94bdc49557f07d87164269daff7340f4d6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5d50e90add8b4a978395e893e81954d19d58a7c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/659654654eb140851467af41d610473c100c7975",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d0c1ce6ef4cefe568e19afa83f543caa3c3c0873",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow\n\nThe 0xffff length sentinel detects a router reboot and schedules\nre-enabling of ethernet mode, but then falls through to the rest\nof the loop body. The next check is\n\n\t} else if (len > CX82310_MTU) {\n\nwhich is the else of the just-matched if -- it never fires for\nlen == 0xffff. The MTU bound that normally caps the\nincomplete-packet save path is silently bypassed.\n\nWith 0xffff > skb->len always true (rx_urb_size is 4096), the\nincomplete-packet branch saves dev->partial_len = skb->len bytes\ninto dev->partial_data. partial_data is kmalloc(hard_mtu) =\nkmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the\n2-byte header pull can be up to 4094. A device that sends a\n4096-byte URB starting with [0xff 0xff] therefore copies 4094\ndevice-provided bytes into a buffer allocated for 1516 bytes,\nexceeding its requested size by 2578 bytes.\n\nThe next URB then reads dev->partial_len (4094) back from the same\n1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from\nthe new URB's ~4KB skb, both well past their allocations, and\ndelivers the spliced result as a 64KB \"frame\" to the network\nstack.\n\nBail out of rx_fixup after scheduling the re-enable work; the\nremainder of a reboot-marker URB is not meaningful packet data.\nThis restores the invariant that partial_len < CX82310_MTU + 2 on\nthe save path, since every other route there has already passed\nthe MTU check."
}
],
"lastModified": "2026-10-03T11:18:25.540",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}