In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: bound the device-reported response length
nsm_sendrecv_msg_locked() stores the virtqueue used-ring length reported
by the NSM device into msg->resp.len without bounding it to the response
buffer. A malicious or buggy backend can report a length larger than the
response buffer; parse_resp_raw() then copies that many bytes out of the
fixed buffer to user space, disclosing adjacent kernel heap (an
out-of-bounds read). The request path already floors its length in
fill_req_raw(); the response path lacks the symmetric check.
Clamp the stored length to the size of the response buffer. Well-behaved
devices report no more than the posted buffer size, so conforming traffic
is unaffected.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 20:20
Updated : 2026-09-13 07:17
NVD link : CVE-2026-89743
Mitre link : CVE-2026-89743
CVE.ORG link : CVE-2026-89743
JSON object : View
Products Affected
No product.
CWE
No CWE.
