Heap-based buffer overflow in Linux kernel - CVE-2026-98025
Published: September 28, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to corrupt memory.
The vulnerability exists due to a heap-based buffer overflow in the cx82310_rx_fixup function of the cx82310_eth USB network driver when processing a crafted USB network receive URB beginning with the 0xffff reboot sentinel. An attacker with physical access can send a crafted USB network receive URB to corrupt memory.