8.8
CVE-2026-43495
- EPSS 0.02%
- Veröffentlicht 21.05.2026 12:12:45
- Zuletzt bearbeitet 30.05.2026 11:17:06
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a slab-out-of-bounds read of up to 262140 bytes. Add a sizeof(*port_msg) check before accessing the port message header fields to guard against undersized messages. Add a struct_size() check after extracting port_count and before the loop. In t7xx_parse_host_rt_data(), guard the rt_feature header read with a remaining-buffer check before accessing data_len, validate feat_data_len against the actual remaining buffer to prevent OOB reads and signed integer overflow on offset. Pass msg_len from both call sites: skb->len at the DPMAIF path after skb_pull(), and the validated feat_data_len at the handshake path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
da45d2566a1d4e260b894ff5d96be64b21c7fa79
Version <
f94450ce5053b36002995b72d1fa1db3bb08c5bf
Status
affected
Version
da45d2566a1d4e260b894ff5d96be64b21c7fa79
Version <
9855e063e063158cc5bded576382599dc3133202
Status
affected
Version
da45d2566a1d4e260b894ff5d96be64b21c7fa79
Version <
2b56d7903ab804481f5233a259d5f341e9fd513c
Status
affected
Version
da45d2566a1d4e260b894ff5d96be64b21c7fa79
Version <
dd4f4c93c1488d7100b9964f2da4c8b3c29652f1
Status
affected
Version
da45d2566a1d4e260b894ff5d96be64b21c7fa79
Version <
0e7c074cfcd9bd93765505f9eb8b42f03ed2a744
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.19
Status
affected
Version
0
Version <
5.19
Status
unaffected
Version <=
6.6.*
Version
6.6.140
Status
unaffected
Version <=
6.12.*
Version
6.12.88
Status
unaffected
Version <=
6.18.*
Version
6.18.30
Status
unaffected
Version <=
7.0.*
Version
7.0.7
Status
unaffected
Version <=
*
Version
7.1-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|