CVE-2026-89721
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
phy: rockchip-samsung-dcphy: fix out-of-range max_register
The PHY register block is 64KB, so with a register stride of 4 the last accessible register sits at offset 0xfffc. max_register names 0x10000, one register past the end of the mapping: dumping the registers through the regmap debugfs interface reads beyond the ioremapped region and oopses on the unmapped page. The oops fires with the regmap lock held, so later PHY operations deadlock.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < 14afe18655c0951f4f85898f761bf92264e65ccd | affected |
| Linux | Linux | b2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < c1a62f9dcf531d56c56da2e4435386b6d264c69f | affected |
| Linux | Linux | b2a1a2ae7818c9d8da12bf7b1983c8b9f5fb712b < 4486e75ba647bd8b98fc1f053101b40caceeed4b | affected |
| Linux | Linux | 6.15 | affected |
| Linux | Linux | 0 < 6.15 | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/14afe18655c0951f4f85898f761bf92264e65ccd
- https://git.kernel.org/stable/c/c1a62f9dcf531d56c56da2e4435386b6d264c69f
- https://git.kernel.org/stable/c/4486e75ba647bd8b98fc1f053101b40caceeed4b
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.