CVE-2026-23474

In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when available") produces the warning below and an oops. Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detected buffer overflow: 15 byte read of buffer size 14 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE As Kees said, "'names' is pointing to the final 'namelen' many bytes of the allocation ... 'namelen' could be basically any length at all. This fortify warning looks legit to me -- this code used to be reading beyond the end of the allocation." Since the size of the dynamic allocation is calculated with strlen() we can use strcmp() instead of memcmp() and remain within bounds.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: mtd: Evitar un fallo de arranque en el analizador de tablas de particiones RedBoot Dado CONFIG_FORTIFY_SOURCE=y y un compilador reciente, el commit 439a1bcac648 ('fortify: Usar __builtin_dynamic_object_size() cuando esté disponible') produce la advertencia a continuación y un oops. Buscando la tabla de particiones RedBoot en 50000000.flash en el desplazamiento 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detectó desbordamiento de búfer: lectura de 15 bytes de un búfer de tamaño 14 Módulos enlazados: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 No contaminado 6.19.0 #1 NONE Como dijo Kees, ''names' está apuntando a los 'namelen' bytes finales de la asignación ... 'namelen' podría ser básicamente de cualquier longitud.' Esta advertencia de fortify me parece legítima -- este código solía leer más allá del final de la asignación. Dado que el tamaño de la asignación dinámica se calcula con strlen(), podemos usar strcmp() en lugar de memcmp() y permanecer dentro de los límites.

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

26 May 2026, 14:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c - () https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c - Patch
References () https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b - () https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b - Patch
References () https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385 - () https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385 - Patch
References () https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566 - () https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566 - Patch
References () https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c - () https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c - Patch
References () https://git.kernel.org/stable/c/ca235d11fc2fd8fce1dcd9d732dc780be0cde2de - () https://git.kernel.org/stable/c/ca235d11fc2fd8fce1dcd9d732dc780be0cde2de - Patch
References () https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb - () https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb - Patch
References () https://git.kernel.org/stable/c/e0065e106f798ce6862251bc4fc030ac5cead940 - () https://git.kernel.org/stable/c/e0065e106f798ce6862251bc4fc030ac5cead940 - Patch
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/ca235d11fc2fd8fce1dcd9d732dc780be0cde2de -
  • () https://git.kernel.org/stable/c/e0065e106f798ce6862251bc4fc030ac5cead940 -

03 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 16:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-23474

Mitre link : CVE-2026-23474

CVE.ORG link : CVE-2026-23474


JSON object : View

Products Affected

linux

  • linux_kernel