KernelScan.io

HIGH Introduced in 5.8

hinic Mailbox Overflow

CVE-2026-97957

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

KernelScan AI8.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: net: hinic: fix mailbox segment buffer overflow check_mbox_seq_id_and_seg_len() validates that seq_id does not exceed SEQ_ID_MAX_VAL (42) and seg_len does not exceed MBOX_SEG_LEN (48). However, this allows the last segment (seq_id=42) to carry a full 48-byte payload, writing to offset 42*48=2016 for 48 bytes (ending at byte 2064). The receive buffer is only MBOX_MAX_BUF_SZ (2048) bytes, resulting in a 16-byte heap buffer overflow. The hinic3 driver already handles this correctly by defining MBOX_LAST_SEG_MAX_LEN and rejecting the last segment when it exceeds the remaining buffer space. Apply the same fix to the hinic driver.

02

Engine v0.6.0

Risk summary

A heap buffer overflow in the hinic network driver's mailbox handler allows a 16-byte write past the end of a receive buffer when processing a crafted multi-segment mailbox message. The most significant attack path is from a VM guest with an SR-IOV virtual function, which can corrupt host kernel memory and potentially achieve VM-to-host escape.

Affecteddrivers/net/ethernet/huawei/hinic/hinic_hw_mbox.c (hinic network driver)

Vulnerability analysis

The Huawei hinic network driver's mailbox message handler validates individual segment lengths against a per-segment maximum but fails to account for the cumulative offset when the final segment is processed, allowing a 16-byte write beyond the end of a heap-allocated receive buffer. The fix adds a dedicated limit for the last segment's length, ensuring the total payload cannot exceed the buffer size, matching the validation already present in the newer hinic3 driver. The vulnerable code path is reachable through the NIC hardware's mailbox channel — most significantly by a virtual machine guest that has been assigned an SR-IOV virtual function, which can send crafted mailbox messages that the host's physical function driver processes, potentially corrupting host kernel memory.

03

BranchIntroducedFixed inPatch commit
6.125.86.12.111eca54a092d5f
6.185.86.18.539f6ad383901d
7.25.87.2.7513f7b16ed0c
mainline5.87.3-rc35d4d98595743