CVE-2026-68143
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: slip: serialize receive against buffer reallocation<br />
<br />
sl_realloc_bufs() replaces rbuff and updates buffsize while holding<br />
sl->lock. slip_receive_buf() reads those fields and writes through rbuff<br />
without holding the lock.<br />
<br />
An MTU change can therefore race with receive processing. An MTU shrink<br />
can expose the new smaller rbuff with the old larger bound, causing an<br />
out-of-bounds write. A receive callback which already loaded the old<br />
rbuff can instead continue writing after that buffer has been freed.<br />
<br />
Serialize receive processing with sl_realloc_bufs() by holding sl->lock<br />
while consuming each receive batch.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0e37bbd6d617eb52bace49390e99eaedc1af73ce
- https://git.kernel.org/stable/c/189a550eb7e1dc10018718ddfc46d003ffe58653
- https://git.kernel.org/stable/c/1be09d175b627fad7f6bec7ad27b8a4a99863912
- https://git.kernel.org/stable/c/44401f7dd9940ced7098930ef64f5a332f279fc2
- https://git.kernel.org/stable/c/5d07b178bef511d69558cfc89fe1129258dc39f8
- https://git.kernel.org/stable/c/8180daf2b66155f84ec4f9e3f95488c8a3421716
- https://git.kernel.org/stable/c/eb3836eab47487823f362e6985e170a1e15f20fd
- https://git.kernel.org/stable/c/ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d


