Integer overflow in Linux kernel - CVE-2026-80546
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to integer overflow and missing minimum size validation in the xcrb_msg_to_type6cprb_msgx() function when copying and processing user-supplied CPRB data from userspace. A local user can provide a crafted control block and length values to execute arbitrary code or cause a denial of service.
The issue involves overflow conditions in aligned length and sum calculations, as well as insufficient validation before reading CPRBX structure fields from a userspace buffer.