CVE-2026-72298: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: fix 32-bit integer overflow in qrtrendpointpost()
qrtrendpointpost() validates an incoming packet with
if (!size || len != ALIGN(size, 4) + hdrlen) goto err;
where size comes from the wire. On 32-bit, sizet is 32 bits and ALIGN(size, 4) wraps to 0 for size >= 0xfffffffd, so the check passes and skbputdata(skb, data + hdrlen, size) writes past the hdrlen-sized skb and oopses the kernel. 64-bit is unaffected.
This is the 32-bit residual of ad9d24c9429e2 ("net: qrtr: fix OOB Read in qrtrendpointpost"), which fixed only the 64-bit case.
Reject any size that cannot fit the buffer before the ALIGN.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post)to a version that resolves this vulnerability.Patch net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() - Configuration
Implement the 32-bit fix for qrtr_endpoint_post(): reject any incoming size value that cannot fit the buffer before calling ALIGN(size, 4), because on 32-bit size_t is 32 bits and ALIGN(size, 4) can wrap to 0 for size >= 0xfffffffd, leading to the residual OOB case.
Linux kernel net: qrtr Reject incoming size values that cannot fit the buffer before ALIGN(size, 4) = Add a bounds check to reject sizes that cannot fit the buffer before performing ALIGN(size, 4)