← Späť na vyhľadávanie CVE

CVE-2026-23474

mtd

Popis

In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 (-fortify: Use __builtin_dynamic_object_size() when available-) produces the warning below and an oops. Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detected buffer overflow: 15 byte read of buffer size 14 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE As Kees said, --names- is pointing to the final -namelen- many bytes of the allocation ... -namelen- could be basically any length at all. This fortify warning looks legit to me -- this code used to be reading beyond the end of the allocation.- Since the size of the dynamic allocation is calculated with strlen() we can use strcmp() instead of memcmp() and remain within bounds.

CVSS 5.5EPSS 0.14200000000000002%Riziko 0.56
Zobraziť zdroj
Zverejnené
2026-04-03 16:16:35
Dotknuté verzie
unknown
Typ
Core software
Posledná úprava
2026-07-24 22:10:00
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Operačné systémy
Linux