SB20260727332 - Integer Overflow to Buffer Overflow in Linux kernel dec prom
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer Overflow to Buffer Overflow (CVE-ID: CVE-2026-64252)
CWE-ID: CWE-680 - Integer Overflow to Buffer Overflow
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory address handling in the DEC PROM early console output handler in arch/mips/dec/prom/console.c when processing initial console output from a kernel thread on 64-bit MIPS systems with 32-bit firmware. A local user can trigger console output in this context to cause a denial of service.
This may occur when the initial console remains in use late in boot, such as when no final console driver has been enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/07c245bc39f94481fd75ff1ed54f7ab97111f3dd
- https://git.kernel.org/stable/c/1c80327dedf05b8c8ca025b76c21235b19dd3a86
- https://git.kernel.org/stable/c/35212f2adc2cf15122b96b987519de235b855e46
- https://git.kernel.org/stable/c/6e61fc2e06e44b6d30248cc5bc47a58e75c2b43e
- https://git.kernel.org/stable/c/7fb13fd35110ebe95eb053faf79d018f51144d85
- https://git.kernel.org/stable/c/8a15826e5d3bdcfbef2f8e9330c69ea9ee7282e7
- https://git.kernel.org/stable/c/9e22b6fc6532cd566dad6d89d8fb3885248e364a
- https://git.kernel.org/stable/c/ab465495b1ed5efb7d2f9b90d8b20b1e0473e26f