#VU124895 Out-of-bounds read in Linux kernel - CVE-2026-23474
Published: April 6, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the RedBoot partition table parser when parsing a RedBoot partition table. A local attacker can trigger the parser with crafted partition table data to cause a denial of service.
The issue can lead to a kernel warning and boot crash on systems built with CONFIG_FORTIFY_SOURCE enabled and a recent compiler.
Remediation
External links
- https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c
- https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b
- https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385
- https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566
- https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c
- https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb