Description
In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()

qrtr_endpoint_post() validates an incoming packet with

if (!size || len != ALIGN(size, 4) + hdrlen)
goto err;

where size comes from the wire. On 32-bit, size_t is 32 bits and
ALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check
passes and skb_put_data(skb, data + hdrlen, size) writes past the
hdrlen-sized skb and oopses the kernel. 64-bit is unaffected.

This is the 32-bit residual of ad9d24c9429e2 ("net: qrtr: fix OOB
Read in qrtr_endpoint_post"), which fixed only the 64-bit case.

Reject any size that cannot fit the buffer before the ALIGN.
Published: 2026-08-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, an integer overflow in the QRTR packet handler allows a crafted packet to cause memory corruption and trigger a kernel crash. The overflow occurs when the size field, taken directly from the packet, is aligned on a 32‑bit boundary, wrapping to zero for large values. The kernel then copies data past the allocated buffer, leading to a kernel oops. The vulnerability is limited to 32‑bit builds; 64‑bit kernels are unaffected.

Affected Systems

Affected systems are 32‑bit Linux kernels that include the QRTR subsystem. No specific kernel version is listed in the CVE; the issue persists in any kernel where the unpatched qrtr_endpoint_post() function is present. Users of older or custom kernels without the commit that introduces this guard remain vulnerable.

Risk and Exploitability

The vulnerability provides a denial‑of‑service condition for the local system, as an attacker can send an oversized QRTR packet and force a kernel oops. The CVSS score of 8.4 indicates high severity. The EPSS score is less than 1%, implying a low likelihood of exploitation. The CVE is not listed in CISA’s KEV catalog, indicating no known wide‑scale exploitation to date. The likely attack vector requires the ability to inject traffic to the QRTR interface, which is typically a local inter‑processor communication channel; thus the threat is primarily local or requires elevated privileges, but could be triggered by compromised processes with access to the relevant interface.

Generated by OpenCVE AI on August 22, 2026 at 06:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the qrtr_endpoint_post overflow fix; the patch is available inline source referenced in the CVE.
  • If an update is not immediately possible, disable or remove the QRTR subsystem or block traffic to the QRTR interface from untrusted sources to prevent the malformed packet from reaching the kernel.
  • As a workaround, apply a local patch that adds a pre‑copy bounds check for the size field, ensuring it fits within the destination buffer before copying data.

Generated by OpenCVE AI on August 22, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-680

Mon, 17 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-680

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-680

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() qrtr_endpoint_post() validates an incoming packet with if (!size || len != ALIGN(size, 4) + hdrlen) goto err; where size comes from the wire. On 32-bit, size_t is 32 bits and ALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check passes and skb_put_data(skb, data + hdrlen, size) writes past the hdrlen-sized skb and oopses the kernel. 64-bit is unaffected. This is the 32-bit residual of ad9d24c9429e2 ("net: qrtr: fix OOB Read in qrtr_endpoint_post"), which fixed only the 64-bit case. Reject any size that cannot fit the buffer before the ALIGN.
Title net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:31.352Z

Reserved: 2026-08-09T03:40:39.917Z

Link: CVE-2026-72298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:02.437

Modified: 2026-08-17T06:18:32.700

Link: CVE-2026-72298

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72298 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-680

    Integer Overflow to Buffer Overflow

  • CWE-787

    Out-of-bounds Write