CVE-2026-46286

In the Linux kernel, the following vulnerability has been resolved: leds: qcom-lpg: Check for array overflow when selecting the high resolution When selecting the high resolution values from the array, FIELD_GET() is used to pull from a 3 bit register, yet the array being indexed has only 5 values in it. Odds are the hardware is sane, but just to be safe, properly check before just overflowing and reading random data and then setting up chip values based on that.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: leds: qcom-lpg: Comprobar el desbordamiento de la matriz al seleccionar la alta resolución Al seleccionar los valores de alta resolución de la matriz, se utiliza FIELD_GET() para extraer de un registro de 3 bits, sin embargo, la matriz que se está indexando tiene solo 5 valores. Lo más probable es que el hardware sea correcto, pero solo para estar seguros, comprobar correctamente antes de simplemente desbordarse y leer datos aleatorios y luego configurar los valores del chip basándose en eso.

08 Jul 2026, 19:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/28a2e047d03721e0517c67ee726eaa6621c30e5f - () https://git.kernel.org/stable/c/28a2e047d03721e0517c67ee726eaa6621c30e5f - Patch
References () https://git.kernel.org/stable/c/36ce3094dc50598f38fd961b46688cd533940efc - () https://git.kernel.org/stable/c/36ce3094dc50598f38fd961b46688cd533940efc - Patch
References () https://git.kernel.org/stable/c/438e357b3cc6cd6900df271e4bc567bfe1142281 - () https://git.kernel.org/stable/c/438e357b3cc6cd6900df271e4bc567bfe1142281 - Patch
References () https://git.kernel.org/stable/c/d45963a93c1495e9f1338fde91d0ebba8fd22474 - () https://git.kernel.org/stable/c/d45963a93c1495e9f1338fde91d0ebba8fd22474 - Patch
References () https://git.kernel.org/stable/c/f67a24e75d3251ba42538738120b6b659c0dca7d - () https://git.kernel.org/stable/c/f67a24e75d3251ba42538738120b6b659c0dca7d - Patch

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46286

Mitre link : CVE-2026-46286

CVE.ORG link : CVE-2026-46286


JSON object : View

Products Affected

linux

  • linux_kernel