Heap-based buffer overflow in Linux kernel - CVE-2026-97957
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a heap-based buffer overflow.
The vulnerability exists due to improper bounds checking in check_mbox_seq_id_and_seg_len() in the hinic driver mailbox receive handler when processing mailbox segments. A local user can send a mailbox segment whose final sequence segment exceeds the remaining receive-buffer space to cause a heap-based buffer overflow.