Return of Stack Variable Address in Linux kernel - CVE-2026-80975
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to corrupt kernel stack memory.
The vulnerability exists due to use of an expired stack buffer in the qnap_mcu_exec() reply buffer when the serdev receive path processes a late reply or unsolicited MCU message after a command timeout or write failure. A local user can trigger processing of a late reply or unsolicited MCU message to corrupt kernel stack memory.