CVE-2026-43495

In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a slab-out-of-bounds read of up to 262140 bytes. Add a sizeof(*port_msg) check before accessing the port message header fields to guard against undersized messages. Add a struct_size() check after extracting port_count and before the loop. In t7xx_parse_host_rt_data(), guard the rt_feature header read with a remaining-buffer check before accessing data_len, validate feat_data_len against the actual remaining buffer to prevent OOB reads and signed integer overflow on offset. Pass msg_len from both call sites: skb->len at the DPMAIF path after skb_pull(), and the validated feat_data_len at the handshake path.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: wwan: t7xx: validar port_count contra la longitud del mensaje en t7xx_port_enum_msg_handler t7xx_port_enum_msg_handler() utiliza el campo port_count suministrado por el módem como límite de bucle sobre port_msg->data[] sin verificar que el búfer del mensaje contenga datos suficientes. Un módem que envía port_count=65535 en un búfer de 12 bytes desencadena una lectura fuera de límites de slab de hasta 262140 bytes. Añadir una verificación sizeof(port_msg) antes de acceder a los campos de la cabecera del mensaje del puerto para proteger contra mensajes de tamaño insuficiente. Añadir una verificación struct_size() después de extraer port_count y antes del bucle. En t7xx_parse_host_rt_data(), proteger la lectura de la cabecera rt_feature con una verificación del búfer restante antes de acceder a data_len, validar feat_data_len contra el búfer restante real para prevenir lecturas OOB y desbordamiento de entero con signo en el desplazamiento. Pasar msg_len desde ambos sitios de llamada: skb->len en la ruta DPMAIF después de skb_pull(), y el feat_data_len validado en la ruta de handshake.

26 Jun 2026, 17:29

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744 - () https://git.kernel.org/stable/c/0e7c074cfcd9bd93765505f9eb8b42f03ed2a744 - Patch
References () https://git.kernel.org/stable/c/2b56d7903ab804481f5233a259d5f341e9fd513c - () https://git.kernel.org/stable/c/2b56d7903ab804481f5233a259d5f341e9fd513c - Patch
References () https://git.kernel.org/stable/c/307c5d0f36a5c74042217136da5bfbd9f7504650 - () https://git.kernel.org/stable/c/307c5d0f36a5c74042217136da5bfbd9f7504650 - Patch
References () https://git.kernel.org/stable/c/9855e063e063158cc5bded576382599dc3133202 - () https://git.kernel.org/stable/c/9855e063e063158cc5bded576382599dc3133202 - Patch
References () https://git.kernel.org/stable/c/dd4f4c93c1488d7100b9964f2da4c8b3c29652f1 - () https://git.kernel.org/stable/c/dd4f4c93c1488d7100b9964f2da4c8b3c29652f1 - Patch
References () https://git.kernel.org/stable/c/f94450ce5053b36002995b72d1fa1db3bb08c5bf - () https://git.kernel.org/stable/c/f94450ce5053b36002995b72d1fa1db3bb08c5bf - Patch
References () http://www.openwall.com/lists/oss-security/2026/06/18/1 - () http://www.openwall.com/lists/oss-security/2026/06/18/1 - Mailing List
CWE CWE-125
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*

19 Jun 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/307c5d0f36a5c74042217136da5bfbd9f7504650 -
  • () http://www.openwall.com/lists/oss-security/2026/06/18/1 -

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

21 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 13:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-43495

Mitre link : CVE-2026-43495

CVE.ORG link : CVE-2026-43495


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read