{"id":"CVE-2026-80814","summary":"rndis_host: add overflow check in rndis_rx_fixup()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer.","modified":"2026-09-15T18:26:48.748769855Z","published":"2026-09-04T15:13:34.711Z","related":["openSUSE-SU-2026:11773-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80814.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ff"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80814.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80814"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"64e049102d3de3e61409cb6019403a9e689dfda6"},{"fixed":"2140db1232af04b92faa6c4a2a40df6371ea89ff"},{"fixed":"8ca3bd404d076495ed0b274b65971c57b6fd5ac0"},{"fixed":"f8e6fde5db87f855e99b200e392467274f0eb9d7"},{"fixed":"10a6b99079697c5027b25352e882bdf54fef702a"},{"fixed":"c5398ce6db7647b7004d73a3102ccc25fb4bb596"},{"fixed":"e971d956353d382ee2185d71c47b538501a43f76"},{"fixed":"be7dc3650f799a253df4edd4fe230fc9ea4be063"},{"fixed":"2ded89ca77fae1da6886fe94831acfe4d6aa80b1"},{"fixed":"965a251f23ff69cfb4486974d4532e9bb551c7fc"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80814.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.14"},{"fixed":"5.10.267"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.218"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.185"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.154"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.106"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.47"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.11"}]},{"type":"ECOSYSTEM","events":[{"introduced":"7.2.0"},{"fixed":"7.2.1"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80814.json"}}],"schema_version":"1.9.0"}