SB2026040653 - Out-of-bounds read in Linux kernel mtd parsers driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-23474)
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the RedBoot partition table parser when parsing a RedBoot partition table. A local attacker can trigger the parser with crafted partition table data to cause a denial of service.
The issue can lead to a kernel warning and boot crash on systems built with CONFIG_FORTIFY_SOURCE enabled and a recent compiler.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c
- https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b
- https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385
- https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566
- https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c
- https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb