CVE-2026-46332

In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive buffering cc1352_bootloader_rx() appends each serdev chunk into the fixed rx_buffer before parsing bootloader packets. The helper can keep leftover bytes between callbacks and may receive multiple packets in one callback, so a single count value is not constrained by one packet length. Check that the incoming chunk fits in the remaining receive buffer space before memcpy(). If it does not, drop the staged data and consume the bytes instead of overflowing rx_buffer.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: greybus: gb-beagleplay: almacenamiento en búfer de recepción del cargador de arranque limitado cc1352_bootloader_rx() añade cada fragmento de serdev en el rx_buffer fijo antes de analizar los paquetes del cargador de arranque. La función auxiliar puede mantener bytes sobrantes entre retrollamadas y puede recibir múltiples paquetes en una retrollamada, por lo que un único valor de conteo no está limitado por la longitud de un paquete. Comprobar que el fragmento entrante cabe en el espacio restante del búfer de recepción antes de memcpy(). Si no es así, descartar los datos preparados y consumir los bytes en lugar de desbordar el rx_buffer.

08 Jul 2026, 21:40

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
CWE CWE-120
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/0339a746ff7cd3f9d10f565e89c99dc93191e58d - () https://git.kernel.org/stable/c/0339a746ff7cd3f9d10f565e89c99dc93191e58d - Patch
References () https://git.kernel.org/stable/c/1214bf28965ceaf584fb20d357731264dd2e10e1 - () https://git.kernel.org/stable/c/1214bf28965ceaf584fb20d357731264dd2e10e1 - Patch
References () https://git.kernel.org/stable/c/663c2728a6d0f781044431111b53a27f71027e48 - () https://git.kernel.org/stable/c/663c2728a6d0f781044431111b53a27f71027e48 - Patch
References () https://git.kernel.org/stable/c/fb91d4e49fcbea0b5091394ac5b8f7d4124265c3 - () https://git.kernel.org/stable/c/fb91d4e49fcbea0b5091394ac5b8f7d4124265c3 - Patch

14 Jun 2026, 06:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

09 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 14:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46332

Mitre link : CVE-2026-46332

CVE.ORG link : CVE-2026-46332


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')