CVE-2026-46293

In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access during output registration UBSAN reported an out of bounds access during registration of the last two outputs. This out of bounds access occurs because space is only allocated in the hws array for two PLLs and the four output dividers that each has, but the defined IDs contain two DLLS and their two outputs each, which are not supported by the driver. The ID order is PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs by two while adding them to the array to avoid the problem.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: clk: microchip: mpfs-ccc: corregir el acceso fuera de límites durante el registro de salida UBSAN informó un acceso fuera de límites durante el registro de las dos últimas salidas. Este acceso fuera de límites ocurre porque solo se asigna espacio en el array hws para dos PLLs y los cuatro divisores de salida que cada uno tiene, pero los IDs definidos contienen dos DLLS y sus dos salidas cada uno, que no son soportados por el controlador. El orden de los IDs es PLLs -> DLLs -> salidas de PLL -> salidas de DLL. Decrementar los IDs de salida de PLL en dos mientras se añaden al array para evitar el problema.

08 Jul 2026, 19:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-125
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36 - () https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36 - Patch
References () https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8 - () https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8 - Patch
References () https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109 - () https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109 - Patch
References () https://git.kernel.org/stable/c/a0780aeea166a7cf4706c45af4cadbb2a43a1fc9 - () https://git.kernel.org/stable/c/a0780aeea166a7cf4706c45af4cadbb2a43a1fc9 - Patch
References () https://git.kernel.org/stable/c/dbfcb09656cb30439577325c9dea2250203c2e3c - () https://git.kernel.org/stable/c/dbfcb09656cb30439577325c9dea2250203c2e3c - Patch
References () https://git.kernel.org/stable/c/f24efd415455b98a1f1cfc6071fe6fde71986706 - () https://git.kernel.org/stable/c/f24efd415455b98a1f1cfc6071fe6fde71986706 - Patch

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46293

Mitre link : CVE-2026-46293

CVE.ORG link : CVE-2026-46293


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read