CVE-2026-97957
CVE CVE-2026-97957EUVD EUVD-2026-86811Published 2026-09-25T10:23:03.000ZLast changed 2026-09-25T14:41:45.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow check_mbox_seq_id_and_seg_len() validates that seq_id does not exceed SEQ_ID_MAX_VAL (42) and seg_len does not exceed MBOX_SEG_LEN (48). However, this allows the last segment (seq_id=42) to carry a full 48-byte payload, writing to offset 42*48=2016 for 48 bytes (ending at byte 2064). The receive buffer is only MBOX_MAX_BUF_SZ (2048) bytes, resulting in a 16-byte heap buffer overflow. The hinic3 driver already handles this correctly by defining MBOX_LAST_SEG_MAX_LEN and rejecting the last segment when it exceeds the remaining buffer space. Apply the same fix to the hinic driver.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.53; 5.8; a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c <513f7b16ed0cffae9348151c72bed17c7073096f; a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c <eca54a092d5f7b497b458ff5a6f66d4f7bfb6674; patch: 6.12.111; patch: 7.3-rc3; patch: 7.2.7; a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c <9f6ad383901d0cb1c8ea5f7f3160fabfe1540eb5; patch: 0; a425b6e1c69ba907b72b737a4d44f8cfbc43ce3c <5d4d985957434867bbe85e4fa5e638f3e48ad522
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.