net: wwan: t7xx: check skb_clone in control TX

Summary

CVECVE-2026-74263
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:25 UTC
Updated2026-08-15 06:22:25 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: check skb_clone in control TX t7xx_port_ctrl_tx() clones each skb fragment before passing it to the port transmit path. The clone is used immediately to set cloned->len, so an skb_clone() failure results in a NULL pointer dereference. Check the clone before using it. If previous fragments were already queued, preserve the driver's existing partial-write behavior by returning the number of bytes submitted so far.

Risk And Classification

EPSS: 0.001680000 probability, percentile 0.064410000 (date 2026-08-15)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 36bd28c1cb0dbf48645cfe43159907fb3253b33a 7edd4db82f9429591de10be4c904c817f12ba029 git Not specified
CNA Linux Linux affected 36bd28c1cb0dbf48645cfe43159907fb3253b33a 112490467586146d323cb7230b1d72137e36900c git Not specified
CNA Linux Linux affected 36bd28c1cb0dbf48645cfe43159907fb3253b33a f7aebaee2961bfcb86f282202d3dbd9b69db1a7c git Not specified
CNA Linux Linux affected 36bd28c1cb0dbf48645cfe43159907fb3253b33a 4c1b25d85f4c9a0f85f3f8c39988ad266a3f3095 git Not specified
CNA Linux Linux affected 36bd28c1cb0dbf48645cfe43159907fb3253b33a 05f789fa90d95d5771230e78453cedff2486039d git Not specified
CNA Linux Linux affected 6.4 Not specified
CNA Linux Linux unaffected 6.4 semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/112490467586146d323cb7230b1d72137e36900c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/05f789fa90d95d5771230e78453cedff2486039d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f7aebaee2961bfcb86f282202d3dbd9b69db1a7c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7edd4db82f9429591de10be4c904c817f12ba029 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4c1b25d85f4c9a0f85f3f8c39988ad266a3f3095 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report