Answer in brief
CVE-2026-80584 records a Unknown severity vulnerability in s390/qeth: validate user buffer length in SNMP and ARP query ioctls. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4a71df50047f0db65ea09b1be155852e81a45eba <9d00eeb2d27f4cc817c5e408760226d43f811ec6 || >=4a71df50047f0db65ea09b1be155852e81a45eba <46443eaddebd84c51940857b11787229be169dec || >=4a71df50047f0db65ea09b1be155852e81a45eba <91935843f9396a9e45253e2c0d4337ca1371754b || >=4a71df50047f0db65ea09b1be155852e81a45eba <cc423f4105fe145b33e1d7cad34245a798358f73 || >=4a71df50047f0db65ea09b1be155852e81a45eba <3083818e67bcd656965797fbac9a3d6c1d44f78a || >=4a71df50047f0db65ea09b1be155852e81a45eba <a3083647747942ea32faf14560d6397ff3068046 || >=4a71df50047f0db65ea09b1be155852e81a45eba <75fb3151513d7d9f77a8f9545418279b119c06b8 || >=4a71df50047f0db65ea09b1be155852e81a45eba <d141f087b1af656f055d7c5793a3e87817ba0bbe | 9d00eeb2d27f4cc817c5e408760226d43f811ec6, 46443eaddebd84c51940857b11787229be169dec, 91935843f9396a9e45253e2c0d4337ca1371754b, cc423f4105fe145b33e1d7cad34245a798358f73, 3083818e67bcd656965797fbac9a3d6c1d44f78a, a3083647747942ea32faf14560d6397ff3068046, 75fb3151513d7d9f77a8f9545418279b119c06b8, d141f087b1af656f055d7c5793a3e87817ba0bbe |
| Linux/Linuxgeneric | 2.6.26 | Not reported |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by a user-supplied length (udata_len) without checking a lower bound, then set udata_offset to a fixed non-zero value and pass both to a reply callback. The callback bounds-checks the copy with if ((udata_len - udata_offset) < len) Both fields are u32, so a udata_len smaller than udata_offset makes the subtraction wrap and the check pass, and the following memcpy() writes past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from kzalloc(), which the existing NULL check does not catch. Reject buffers smaller than udata_offset before allocating, so the callback subtraction can no longer underflow.
Quoted source text, attributed separately from HOL analysis.