Executive brief
The Linux kernel's wireless WAN IOSM driver contains a vulnerability in how it processes data frames from modems. A malicious or compromised modem can send specially crafted data that causes the kernel to read data beyond allocated memory boundaries, potentially exposing sensitive kernel memory or causing system instability.
Technical details
The mux_dl_adb_decode() function in the IOSM MUX downlink decoder processes aggregated datagram tables using device-supplied offset and length values without proper validation. The vulnerability exists in multiple forms: (1) out-of-bounds reads when offsets/lengths exceed skb buffer boundaries, (2) infinite loops when table chains point to each other cyclically, and (3) memory wrapping issues due to unchecked header padding. The attack requires a malicious modem or a compromised modem firmware to send crafted downlink frames. The kernel patch adds validation to ensure all offsets and lengths remain within skb bounds, enforces forward progress in table chain traversal, and validates header structure before use.
Affected products
- Linux Linux kernel prior to patch (net: wwan: iosm: bound device offsets in the MUX downlink decoder)
Timeline
- 2026-08-15: disclosed
- 2026-08-15: patched: Patch available in kernel commit addressing bounds validation in mux_dl_adb_decode()