Buffer Overflow Vulnerability in Linux Kernel's QETH Component
CVE-2026-80584
What is CVE-2026-80584?
A vulnerability exists in the Linux kernel related to the QETH component, specifically within the SNMP and ARP query ioctls. It arises when user-supplied buffer lengths are allocated without proper lower bound checks. This insufficient validation can lead to a scenario where buffer underflows occur, enabling malicious actors to exploit the system through unintended memory writes. The recommended resolution includes enforcing strict validation to reject any buffer sizes smaller than necessary before allocation, thereby preventing the potential overflow and ensuring stable operations.
Affected Version(s)
Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 9d00eeb2d27f4cc817c5e408760226d43f811ec6
Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 46443eaddebd84c51940857b11787229be169dec
Linux 4a71df50047f0db65ea09b1be155852e81a45eba < 91935843f9396a9e45253e2c0d4337ca1371754b