CVE-2026-80723
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
of: reserved_mem: prevent OOB when too many dynamic regions are defined
On boot, fdt_scan_reserved_mem() saves each dynamically-placed /reserved-memory subnode into a local array of size MAX_RESERVED_REGIONS.
If the device tree defines more than MAX_RESERVED_REGIONS dynamically-placed regions, fdt_scan_reserved_mem() writes past the end of the local array.
Add a bounds check that logs an error and skips the excess regions, restoring the original behavior.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 9a0fe62f93ede02c27aaca81112af1e59c8c0979 < 68d27250c9e81ab7764603e346c2b1017cb53adf | affected |
| Linux | Linux | 8a6e02d0c00e7b62e6acb74146878bb91e9e7e31 < cfa7e2734877330d6c10e0f33953905486c4530c | affected |
| Linux | Linux | 8a6e02d0c00e7b62e6acb74146878bb91e9e7e31 < de8ccbd6bf4efe7a059e2c483789936009e10f42 | affected |
| Linux | Linux | 8a6e02d0c00e7b62e6acb74146878bb91e9e7e31 < db3dbdfea1b8f38774419c5c2c14e4b81c48708d | affected |
| Linux | Linux | 6.12.13 < 6.12.103 | affected |
| Linux | Linux | 6.13 | affected |
| Linux | Linux | 0 < 6.13 | unaffected |
| Linux | Linux | 6.12.103 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.44 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.8 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/68d27250c9e81ab7764603e346c2b1017cb53adf
- https://git.kernel.org/stable/c/cfa7e2734877330d6c10e0f33953905486c4530c
- https://git.kernel.org/stable/c/de8ccbd6bf4efe7a059e2c483789936009e10f42
- https://git.kernel.org/stable/c/db3dbdfea1b8f38774419c5c2c14e4b81c48708d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.