IM
IronMonkey Threat Research

CVE-2026-23474 MEDIUM

Published: 2026-04-03 | Last Modified: 2026-07-24 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when available") produces the warning below and an oops. Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detected buffer overflow: 15 byte read of buffer size 14 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE As Kees said, "'names' is pointing to the final 'namelen' many bytes of the allocation ... 'namelen' could be basically any length at all. This fortify warning looks legit to me -- this code used to be reading beyond the end of the allocation." Since the size of the dynamic allocation is calculated with strlen() we can use strcmp() instead of memcmp() and remain within bounds.

Additional Descriptions (1)

En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: mtd: Evitar un fallo de arranque en el analizador de tablas de particiones RedBoot Dado CONFIG_FORTIFY_SOURCE=y y un compilador reciente, el commit 439a1bcac648 ('fortify: Usar __builtin_dynamic_object_size() cuando esté disponible') produce la advertencia a continuación y un oops. Buscando la tabla de particiones RedBoot en 50000000.flash en el desplazamiento 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detectó desbordamiento de búfer: lectura de 15 bytes de un búfer de tamaño 14 Módulos enlazados: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 No contaminado 6.19.0 #1 NONE Como dijo Kees, ''names' está apuntando a los 'namelen' bytes finales de la asignación ... 'namelen' podría ser básicamente de cualquier longitud.' Esta advertencia de fortify me parece legítima -- este código solía leer más allá del final de la asignación. Dado que el tamaño de la asignación dinámica se calcula con strlen(), podemos usar strcmp() en lugar de memcmp() y permanecer dentro de los límites.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d239fbde5c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a5986e80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24245cf1c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d239fbdc780> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d239fbdc9c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d239fbde0c0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24243dd640> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5986e00> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d239fbdc100> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d239fbde880> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5987d80> Operating System
linux linux_kernel 2.6.12 <built-in method update of dict object at 0x7d23a5986380> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d2357ccd980> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23beb83040> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d23a5984300> Operating System
linux linux_kernel 7.0 <built-in method update of dict object at 0x7d239fbde9c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*

References

Notification
Message here