← Voltar à pesquisa de CVEs

CVE-2026-23474

mtd

Descrição

In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 (-fortify: Use __builtin_dynamic_object_size() when available-) produces the warning below and an oops. Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detected buffer overflow: 15 byte read of buffer size 14 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE As Kees said, --names- is pointing to the final -namelen- many bytes of the allocation ... -namelen- could be basically any length at all. This fortify warning looks legit to me -- this code used to be reading beyond the end of the allocation.- Since the size of the dynamic allocation is calculated with strlen() we can use strcmp() instead of memcmp() and remain within bounds.

CVSS 5.5EPSS 0.14200000000000002%Risco 0.56
Ver fonte
Publicação
2026-04-03 16:16:35
Versões afetadas
unknown
Tipo
Core software
Última alteração
2026-07-24 22:10:00
Vetor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Sistemas operativos
Linux