CVE-2026-81007

Source
https://cve.org/CVERecord?id=CVE-2026-81007
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81007.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81007
Downstream
Published
2026-09-11T19:42:58Z
Modified
2026-09-13T03:47:17Z
Summary
ipmi: ipmb: validate write message length
Details

In the Linux kernel, the following vulnerability has been resolved:

ipmi: ipmb: validate write message length

ipmb_write() read message fields before validating the length byte.

A zero or short write can read uninitialized stack bytes.

A length smaller than the SMBus header underflows the block write length.

Require a non-empty buffer and the minimum IPMB request length.

Also require the length byte plus payload before parsing the message.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81007.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
51bd6f291583684f495ea498984dfc22049d7fd2
Fixed
60939bcda6f3f104ef456fdbf3cc5733c0720fb1
Fixed
5719431ca2b5fa26560bb38f6202f8b97fa3bbb0
Fixed
a84c6e3d188f2c6e674910929eb790634299d6d5
Fixed
53637506884dbd5c91a89b1a3547d99d80f8ed2c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81007.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81007.json"