CVE-2026-31743

Description

A flaw was found in the Linux kernel, specifically within the nvmem and zynqmp_nvmem modules. An incorrect buffer size used during Direct Memory Access (DMA) allocation and memcpy operations can lead to undersized DMA buffer access. This vulnerability could allow a local attacker to cause memory corruption, potentially leading to system instability or denial of service.

Understanding the Weakness (CWE)

Integrity,Availability,Confidentiality

Technical Impact: DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands; Read Memory; Modify Memory

If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing arbitrary code execution, or exposing sensitive data.

Frequently Asked Questions

Want to get errata notifications? Sign up here.