{"id":"CVE-2026-98236","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: check skb_copy_bits() return value\n\nmhi_mbim_rx() ignores the return value of skb_copy_bits() when it\ncopies each datagram out of the NTB","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: check skb_copy_bits() return value\n\nmhi_mbim_rx() ignores the return value of skb_copy_bits() when it\ncopies each datagram out of the NTB.  Th…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 650af68435eaee783824457d2ef78cc5c03c1e88","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 350fd3125ee26b5243935fd9e2b4d162ffba430a","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < dd136f1fdd1059f3bc25ede3a8def8f0ee151ce7","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 298659c3677bf622afa9d77549cb4a967f9541e9","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 02eba5f36d20283f144f75d47f0354a85e4f78f0","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 7e98216e9da08b79e07a514d2a4f7646f8c9ccb9","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 31550d585589fde1ae95bf7f7a8188b2d2fdf1c7","Linux 5.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:11.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98236","references":[{"url":"https://git.kernel.org/stable/c/02eba5f36d20283f144f75d47f0354a85e4f78f0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/298659c3677bf622afa9d77549cb4a967f9541e9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31550d585589fde1ae95bf7f7a8188b2d2fdf1c7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/350fd3125ee26b5243935fd9e2b4d162ffba430a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/650af68435eaee783824457d2ef78cc5c03c1e88","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e98216e9da08b79e07a514d2a4f7646f8c9ccb9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd136f1fdd1059f3bc25ede3a8def8f0ee151ce7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.435Z","slug":"CVE-2026-98236","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: check skb_copy_bits() return value\n\nmhi_mbim_rx() ignores the return value of skb_copy_bits() when it\ncopies each datagram out of the NTB.  The datagram offset and length\ncome from the DPE, which is only checked to lie within the NTB\nitself, so a modem can point a datagram outside the received skb.\nThe copy then fails and the freshly allocated skbn is passed to\nnetif_rx() with its uninitialized contents still in place, leaking\nkernel heap memory into the network stack.\n\nFree the skb and account an error when the copy fails.\n\n\nVerified in a QEMU guest with a fault injector pointing a DPE\noutside the received NTB: the copy fails, and the unpatched driver\nhands the uninitialized skbn to the network stack (observed as\n\"unknown protocol\" on bytes that were never written).  With this\ncheck the failed datagram is dropped and counted as an rx error.\n\nChanges in v2: factor the free-and-count sequence out into\nmhi_mbim_rx_drop(), shared with the unknown-protocol path, as\nsuggested by Loic Poulain.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}