SB20260912402 - Return of Stack Variable Address in Linux kernel mfd driver
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Return of Stack Variable Address (CVE-ID: CVE-2026-80975)
CWE-ID: CWE-562 - Return of Stack Variable Address
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt kernel stack memory.
The vulnerability exists due to use of an expired stack buffer in the qnap_mcu_exec() reply buffer when the serdev receive path processes a late reply or unsolicited MCU message after a command timeout or write failure. A local user can trigger processing of a late reply or unsolicited MCU message to corrupt kernel stack memory.
Remediation
Install update from vendor's website.