VDB
CVE-2026-81007
CVE-2026-81007
PUBLISHED
CVSS 7.1 HIGH
Reported by Linux · Published September 11, 2026
In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header underflows the block write length. Require a non-empty buffer and the minimum IPMB request length. Also require the length byte plus payload before parsing the message.
EPSS 0.12% · 2.5th percentile
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Score
0.12%
2.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 51bd6f291583684f495ea498984dfc22049d7fd2, 51bd6f291583684f495ea498984dfc22049d7fd2, 51bd6f291583684f495ea498984dfc22049d7fd2 |
| Linux | Linux | 5.3, 0, 5.10.270 |
| Linux | Linux | 7.3-rc1, 51bd6f291583684f495ea498984dfc22049d7fd2, 51bd6f291583684f495ea498984dfc22049d7fd2 |
| linux | linux_kernel | 5.3, 5.3, 5.3 |
Timeline
- Sep 11, 2026 CVE Published
- Sep 12, 2026 EPSS Score
- Sep 12, 2026 Coalition ESS Score
- Sep 13, 2026 EPSS Score
- Sep 14, 2026 CVE Updated