CVE-2026-46293

説明

A flaw was found in the Linux kernel's clock driver for Microchip PolarFire SoC (MPFS) systems. This vulnerability involves an out-of-bounds memory access that occurs during the registration of clock outputs. The issue stems from incorrect memory allocation within the driver, which can lead to system instability or a denial of service (DoS) condition.

脆弱性の原因 (CWE) の理解

Integrity,Availability,Confidentiality

Technical Impact: DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands; Read Memory; Modify Memory

If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing arbitrary code execution, or exposing sensitive data.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください。