CVE-2026-80975
Received Received - Intake

Buffer Overflow in QNAP MCU Linux Kernel Driver

Vulnerability report for CVE-2026-80975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mfd: qnap-mcu: keep the reply buffer alive past a command timeout qnap_mcu_exec() publishes an on-stack buffer to the receive path: unsigned char rx[QNAP_MCU_RX_BUFFER_SIZE]; ... reply->data = rx; reply->length = length; and qnap_mcu_receive_buf() writes into it from the serdev receive path, which runs out of flush_to_ldisc() and is not serialized against qnap_mcu_exec() at all. bus_lock cannot cover it, because qnap_mcu_exec() holds that mutex across wait_for_completion_timeout(). On a timeout qnap_mcu_exec() returns with reply->data still pointing at its own frame. A reply that arrives late, or an unsolicited message from the MCU, is then written into a stack frame that has been left, corrupting whatever runs next on that stack. The same applies when qnap_mcu_write() fails, since that path returns without touching the reply state either. Move the receive buffer into struct qnap_mcu. It is 37 bytes and the structure is devm_kzalloc()ed, so it lives as long as the driver, and a late write lands in memory that is still valid and is reinitialized by the next command. bus_lock keeps commands from sharing it. This deliberately does not clear reply->data or reply->length on the timeout path. Doing so races with qnap_mcu_receive_buf(), which reads both after its if (!reply->length) return size; check: clearing reply->data gives a NULL dereference, and clearing reply->length alone removes the reply->received == reply->length exit condition, so the copy loop runs until the uart chunk is consumed and overruns the buffer. Leaving both set keeps the write bounded by reply->length, which qnap_mcu_exec() has already checked against sizeof(mcu->rx).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qnap qnap_mcu *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a stack buffer overflow in the QNAP MCU driver. The issue occurs when a command times out, leaving a reply buffer pointing to a stack frame that may have been reused. Late or unsolicited messages from the MCU can then corrupt the stack, potentially leading to arbitrary code execution or system crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's mfd: qnap-mcu driver and does not have direct network detection methods. It involves memory corruption due to improper handling of a reply buffer in the qnap_mcu_exec() function. Detection would require kernel logging or driver-specific monitoring for crashes or memory corruption events.

Impact Analysis

An attacker with physical or logical access to the system could exploit this flaw to execute arbitrary code, escalate privileges, or crash the system. This may lead to unauthorized data access, denial of service, or further compromise of the affected device.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a memory corruption issue in the Linux kernel's QNAP MCU driver. It could potentially lead to system instability or crashes, which might indirectly impact data integrity or availability, but no specific compliance implications are mentioned in the provided context.

Mitigation Strategies

Update your Linux kernel to a version that includes the fix for this vulnerability. The patch moves the receive buffer into the struct qnap_mcu to prevent stack corruption. If updating is not immediately possible, consider disabling the qnap-mcu driver if it is not essential to your system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart