CVE-2026-81007
Last modified
CVE-2026-81007 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header underflows the block write length. Require a non-empty buffer and the minimum IPMB request length. Also require the length byte plus payload before parsing the message.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header underflows the block write length. Require a non-empty buffer and the minimum IPMB request length. Also require the length byte plus payload before parsing the message.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 8990c7f6bfc1e7689b7012a7d4d0efb9f07a9c89; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 94f8d20153e348c79bc14dc25f873470518892da; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < e527cd4e80066e1ed070fdc7c705bde340cdcc62; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 7d66d54b974cff0a959e188af844d2d110422767; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 60939bcda6f3f104ef456fdbf3cc5733c0720fb1; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 5719431ca2b5fa26560bb38f6202f8b97fa3bbb0; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < a84c6e3d188f2c6e674910929eb790634299d6d5; >= 51bd6f291583684f495ea498984dfc22049d7fd2, < 53637506884dbd5c91a89b1a3547d99d80f8ed2c |
| Linux | Linux | 5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81007?
How severe is CVE-2026-81007?
How do I fix CVE-2026-81007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81001In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-81002In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-81003In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-81004In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-81005In the Linux kernel, the following vulnerability has been re…
- CVE-2026-81006In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-81008In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-81009In the Linux kernel, the following vulnerability has been re…
- CVE-2026-81010In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-81011In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-81012In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-81013In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-81007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
