CVE-2026-81007High· 7.1▾ TwilightIn the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
0.2%
— → 7.1
none → high
Last analysed / modified upstream
In the Linux kernel, the following vulnerability has been resolved:
ipmi: ipmb: validate write message length
ipmb_write() read message fields before validating the length byte.
A zero or short write can read uninitialized stack bytes.
A length smaller than the SMBus header underflows the block write length.
Require a non-empty buffer and the minimum IPMB request length.
Also require the length byte plus payload before parsing the message.
Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 8990c7f6bfc1e7689b7012a7d4d0efb9f07a9c89Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 94f8d20153e348c79bc14dc25f873470518892daLinux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < e527cd4e80066e1ed070fdc7c705bde340cdcc62Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 7d66d54b974cff0a959e188af844d2d110422767Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 60939bcda6f3f104ef456fdbf3cc5733c0720fb1Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 5719431ca2b5fa26560bb38f6202f8b97fa3bbb0Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < a84c6e3d188f2c6e674910929eb790634299d6d5Linux >= 51bd6f291583684f495ea498984dfc22049d7fd2 < 53637506884dbd5c91a89b1a3547d99d80f8ed2cLinux 5.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68286NoneIn the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() /…
CVE-2026-68337NoneIn the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri()…
CVE-2026-68287High· 7.5In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attri…
CVE-2026-68288NoneIn the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to a…
CVE-2026-68289NoneIn the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buf…
CVE-2026-68303NoneIn the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions