In the Linux kernel, the following vulnerability has been resolved:
net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as
a loop bound over port_msg->data[] without checking that the message buffer
contains sufficient data. A modem sending port_count=65535 in a 12-byte
buffer triggers a slab-out-of-bounds read of up to 262140 bytes.
Add a sizeof(*port_msg) check before accessing the port message header
fields to guard against undersized messages.
Add a struct_size() check after extracting port_count and before the loop.
In t7xx_parse_host_rt_data(), guard the rt_feature header read with a
remaining-buffer check before accessing data_len, validate feat_data_len
against the actual remaining buffer to prevent OOB reads and signed
integer overflow on offset.
Pass msg_len from both call sites: skb->len at the DPMAIF path after
skb_pull(), and the validated feat_data_len at the handshake path.
References
Configurations
Configuration 1 (hide)
|
History
23 Jul 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Jun 2026, 17:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Linux linux Kernel
Linux |
|
| References | () https://git.kernel.org/stable/c/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744 - Patch | |
| References | () https://git.kernel.org/stable/c/2b56d7903ab804481f5233a259d5f341e9fd513c - Patch | |
| References | () https://git.kernel.org/stable/c/307c5d0f36a5c74042217136da5bfbd9f7504650 - Patch | |
| References | () https://git.kernel.org/stable/c/9855e063e063158cc5bded576382599dc3133202 - Patch | |
| References | () https://git.kernel.org/stable/c/dd4f4c93c1488d7100b9964f2da4c8b3c29652f1 - Patch | |
| References | () https://git.kernel.org/stable/c/f94450ce5053b36002995b72d1fa1db3bb08c5bf - Patch | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/18/1 - Mailing List | |
| CWE | CWE-125 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
19 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 May 2026, 11:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
21 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-21 13:16
Updated : 2026-07-23 16:10
NVD link : CVE-2026-43495
Mitre link : CVE-2026-43495
CVE.ORG link : CVE-2026-43495
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-125
Out-of-bounds Read
