CVE-2026-80584
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/qeth: validate user buffer length in SNMP and ARP query ioctls<br />
<br />
qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by<br />
a user-supplied length (udata_len) without checking a lower bound, then<br />
set udata_offset to a fixed non-zero value and pass both to a reply<br />
callback. The callback bounds-checks the copy with<br />
<br />
if ((udata_len - udata_offset)
Impacto
Puntuación base 3.x
8.40
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/3083818e67bcd656965797fbac9a3d6c1d44f78a
- https://git.kernel.org/stable/c/46443eaddebd84c51940857b11787229be169dec
- https://git.kernel.org/stable/c/75fb3151513d7d9f77a8f9545418279b119c06b8
- https://git.kernel.org/stable/c/91935843f9396a9e45253e2c0d4337ca1371754b
- https://git.kernel.org/stable/c/9d00eeb2d27f4cc817c5e408760226d43f811ec6
- https://git.kernel.org/stable/c/a3083647747942ea32faf14560d6397ff3068046
- https://git.kernel.org/stable/c/cc423f4105fe145b33e1d7cad34245a798358f73
- https://git.kernel.org/stable/c/d141f087b1af656f055d7c5793a3e87817ba0bbe



