-

CVE-2026-98025

net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow

In the Linux kernel, the following vulnerability has been resolved:

net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow

The 0xffff length sentinel detects a router reboot and schedules
re-enabling of ethernet mode, but then falls through to the rest
of the loop body.  The next check is

	} else if (len > CX82310_MTU) {

which is the else of the just-matched if -- it never fires for
len == 0xffff.  The MTU bound that normally caps the
incomplete-packet save path is silently bypassed.

With 0xffff > skb->len always true (rx_urb_size is 4096), the
incomplete-packet branch saves dev->partial_len = skb->len bytes
into dev->partial_data.  partial_data is kmalloc(hard_mtu) =
kmalloc(CX82310_MTU + 2) = 1516 bytes, but skb->len after the
2-byte header pull can be up to 4094.  A device that sends a
4096-byte URB starting with [0xff 0xff] therefore copies 4094
device-provided bytes into a buffer allocated for 1516 bytes,
exceeding its requested size by 2578 bytes.

The next URB then reads dev->partial_len (4094) back from the same
1516-byte buffer and dev->partial_rem (65535 - 4094 = 61441) from
the new URB's ~4KB skb, both well past their allocations, and
delivers the spliced result as a 64KB "frame" to the network
stack.

Bail out of rx_fixup after scheduling the re-enable work; the
remainder of a reboot-marker URB is not meaningful packet data.
This restores the invariant that partial_len < CX82310_MTU + 2 on
the save path, since every other route there has already passed
the MTU check.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < d0c1ce6ef4cefe568e19afa83f543caa3c3c0873
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 0dbc89e664b4609ad672b5bdeef60df251294b8f
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 00520cdd21ea6a9b5dc8d53bbd241620d2059554
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 59bf9e94bdc49557f07d87164269daff7340f4d6
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 659654654eb140851467af41d610473c100c7975
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 237c9ae7145772af147e4665f158938350fa5658
Status affected
Version ca139d76b0d9e59d18f2d2ec8f0d81b82acd6808
Version < 5d50e90add8b4a978395e893e81954d19d58a7c5
Status affected
Version 5adf7fbdfa3e9e425b04771e1d64c4e184ad8fdb
Status affected
Version c1b187a86a176e42f5e48066556980e3232b6cab
Status affected
Version 4.19.322
Version < 4.20
Status affected
Version 5.4.284
Version < 5.5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.111
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3bd689409bb1c93bdc6dd8ec6cbf5161bc4f0287
https://git.kernel.org/stable/c/659654654eb140851467af41d610473c100c7975
https://git.kernel.org/stable/c/237c9ae7145772af147e4665f158938350fa5658
https://git.kernel.org/stable/c/5d50e90add8b4a978395e893e81954d19d58a7c5
https://git.kernel.org/stable/c/00520cdd21ea6a9b5dc8d53bbd241620d2059554
https://git.kernel.org/stable/c/0dbc89e664b4609ad672b5bdeef60df251294b8f
https://git.kernel.org/stable/c/59bf9e94bdc49557f07d87164269daff7340f4d6
https://git.kernel.org/stable/c/d0c1ce6ef4cefe568e19afa83f543caa3c3c0873