What is CVE-2026-12519?
CVE-2026-12519 involves improper handling of unsolicited `%NOTIFYEV:` events in the `on_cmd_socknotifyev()` function of the WNC-M14A2A LTE-M modem driver. This can lead to a buffer overflow risk when data is copied to a fixed-size stack buffer via `net_buf_linearize()`. Affected systems should update the modem driver or apply the relevant patch.
Azərbaycanca: CVE-2026-12519 WNC-M14A2A LTE-M modem sürücüsündə `on_cmd_socknotifyev()` funksiyasında `%NOTIFYEV:` hadisələrinin düzgün işlənməməsi ilə bağlıdır. Bu, `net_buf_linearize()` ilə 40 baytlıq stek buferinə məlumat köçürərkən həddən artıq yazma riski yaradır. Təsirə məruz qalan sistemlərdə modem sürücüsü yenilənməli və ya müvafiq yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which component was the CVE-2026-12519 vulnerability discovered?
This vulnerability was discovered in the `on_cmd_socknotifyev()` function of the WNC-M14A2A LTE-M modem driver.
What risk arises when CVE-2026-12519 is exploited?
When exploited, improper handling of `%NOTIFYEV:` events can lead to a buffer overflow risk when data is copied to a 40-byte stack buffer via `net_buf_linearize()`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.