SB20260727332 - Integer Overflow to Buffer Overflow in Linux kernel dec prom



SB20260727332 - Integer Overflow to Buffer Overflow in Linux kernel dec prom

Published: July 27, 2026

Security Bulletin ID SB20260727332
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Integer Overflow to Buffer Overflow (CVE-ID: CVE-2026-64252)

CWE-ID: CWE-680 - Integer Overflow to Buffer Overflow

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory address handling in the DEC PROM early console output handler in arch/mips/dec/prom/console.c when processing initial console output from a kernel thread on 64-bit MIPS systems with 32-bit firmware. A local user can trigger console output in this context to cause a denial of service.

This may occur when the initial console remains in use late in boot, such as when no final console driver has been enabled.


Remediation

Install update from vendor's website.