Integer Overflow to Buffer Overflow in Linux kernel - CVE-2026-64252
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper memory address handling in the DEC PROM early console output handler in arch/mips/dec/prom/console.c when processing initial console output from a kernel thread on 64-bit MIPS systems with 32-bit firmware. A local user can trigger console output in this context to cause a denial of service.
This may occur when the initial console remains in use late in boot, such as when no final console driver has been enabled.
Affected software
How to mitigate CVE-2026-64252
External References
- https://git.kernel.org/stable/c/07c245bc39f94481fd75ff1ed54f7ab97111f3dd
- https://git.kernel.org/stable/c/1c80327dedf05b8c8ca025b76c21235b19dd3a86
- https://git.kernel.org/stable/c/35212f2adc2cf15122b96b987519de235b855e46
- https://git.kernel.org/stable/c/6e61fc2e06e44b6d30248cc5bc47a58e75c2b43e
- https://git.kernel.org/stable/c/7fb13fd35110ebe95eb053faf79d018f51144d85
- https://git.kernel.org/stable/c/8a15826e5d3bdcfbef2f8e9330c69ea9ee7282e7
- https://git.kernel.org/stable/c/9e22b6fc6532cd566dad6d89d8fb3885248e364a
- https://git.kernel.org/stable/c/ab465495b1ed5efb7d2f9b90d8b20b1e0473e26f