Buffer Overflow Vulnerability in Linux Kernel's QETH Component
CVE-2026-80584

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80584?

A vulnerability exists in the Linux kernel related to the QETH component, specifically within the SNMP and ARP query ioctls. It arises when user-supplied buffer lengths are allocated without proper lower bound checks. This insufficient validation can lead to a scenario where buffer underflows occur, enabling malicious actors to exploit the system through unintended memory writes. The recommended resolution includes enforcing strict validation to reject any buffer sizes smaller than necessary before allocation, thereby preventing the potential overflow and ensuring stable operations.

Affected Version(s)

Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 9d00eeb2d27f4cc817c5e408760226d43f811ec6

Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 46443eaddebd84c51940857b11787229be169dec

Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 91935843f9396a9e45253e2c0d4337ca1371754b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.