HIGH Introduced in 5.8
hinic Mailbox Overflow
CVE-2026-97957
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
KernelScan AI8.8HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow check_mbox_seq_id_and_seg_len() validates that seq_id does not exceed SEQ_ID_MAX_VAL (42) and seg_len does not exceed MBOX_SEG_LEN (48). However, this allows the last segment (seq_id=42) to carry a full 48-byte payload, writing to offset 42*48=2016 for 48 bytes (ending at byte 2064). The receive buffer is only MBOX_MAX_BUF_SZ (2048) bytes, resulting in a 16-byte heap buffer overflow. The hinic3 driver already handles this correctly by defining MBOX_LAST_SEG_MAX_LEN and rejecting the last segment when it exceeds the remaining buffer space. Apply the same fix to the hinic driver.
02KernelScan AI Analysis
Risk summary
A heap buffer overflow in the hinic network driver's mailbox handler allows a 16-byte write past the end of a receive buffer when processing a crafted multi-segment mailbox message. The most significant attack path is from a VM guest with an SR-IOV virtual function, which can corrupt host kernel memory and potentially achieve VM-to-host escape.
Vulnerability analysis
The Huawei hinic network driver's mailbox message handler validates individual segment lengths against a per-segment maximum but fails to account for the cumulative offset when the final segment is processed, allowing a 16-byte write beyond the end of a heap-allocated receive buffer. The fix adds a dedicated limit for the last segment's length, ensuring the total payload cannot exceed the buffer size, matching the validation already present in the newer hinic3 driver. The vulnerable code path is reachable through the NIC hardware's mailbox channel — most significantly by a virtual machine guest that has been assigned an SR-IOV virtual function, which can send crafted mailbox messages that the host's physical function driver processes, potentially corrupting host kernel memory.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 5.8 | 6.12.111 | eca54a092d5f |
| 6.18 | 5.8 | 6.18.53 | 9f6ad383901d |
| 7.2 | 5.8 | 7.2.7 | 513f7b16ed0c |
| mainline | 5.8 | 7.3-rc3 | 5d4d98595743 |