CVE-2026-63857

Source
https://cve.org/CVERecord?id=CVE-2026-63857
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63857.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63857
Downstream
Published
2026-07-19T14:04:46.339Z
Modified
2026-07-21T03:47:34.762429505Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: airoha: Do not read uninitialized fragment address in airohadevxmit()

The transmit loop in airohadevxmit() reads fragment address and length during its final iteration, when the loop index equals skbshinfo(skb)->nrfrags, at which point the fragment data is uninitialized. While these values are never consumed, the read itself is unsafe and may trigger a page fault. Fix this by avoiding the fragment read on the last iteration. Additionally, move the skb pointer from the first to the last used packet descriptor, so that airohaqdmatxnapipoll() defers freeing the skb until the final descriptor is processed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63857.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
23020f04932701d5c8363e60756f12b43b8ed752
Fixed
f670fa4b19ceddc6d215dda4997888ccba9bbc61
Fixed
d78c8ab7bd84952e053d0c622b7fc1b4ad8a19a3
Fixed
bde34e84edc8b5571fbde7e941e175a4293ee1eb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63857.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63857.json"