SB2026082756 - Out-of-bounds write in Linux kernel s390 net driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-80584)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in the qeth SNMP and ARP query ioctl handlers when processing user-supplied buffer lengths. A remote attacker can supply a crafted length value that causes an integer underflow in a bounds check and trigger a memcpy() past the allocated buffer to execute arbitrary code.
The issue occurs because a user-supplied length smaller than the fixed offset can wrap a u32 subtraction, and a zero-length allocation can also result in an invalid zero-sized buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3083818e67bcd656965797fbac9a3d6c1d44f78a
- https://git.kernel.org/stable/c/46443eaddebd84c51940857b11787229be169dec
- https://git.kernel.org/stable/c/75fb3151513d7d9f77a8f9545418279b119c06b8
- https://git.kernel.org/stable/c/91935843f9396a9e45253e2c0d4337ca1371754b
- https://git.kernel.org/stable/c/9d00eeb2d27f4cc817c5e408760226d43f811ec6
- https://git.kernel.org/stable/c/a3083647747942ea32faf14560d6397ff3068046
- https://git.kernel.org/stable/c/cc423f4105fe145b33e1d7cad34245a798358f73
- https://git.kernel.org/stable/c/d141f087b1af656f055d7c5793a3e87817ba0bbe