Integer Overflow to Buffer Overflow in Linux kernel - CVE-2026-64252

 

Integer Overflow to Buffer Overflow in Linux kernel - CVE-2026-64252

Published: July 27, 2026


Vulnerability identifier: #VU139743
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64252
CWE-ID: CWE-680
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper memory address handling in the DEC PROM early console output handler in arch/mips/dec/prom/console.c when processing initial console output from a kernel thread on 64-bit MIPS systems with 32-bit firmware. A local user can trigger console output in this context to cause a denial of service.

This may occur when the initial console remains in use late in boot, such as when no final console driver has been enabled.


Affected software

Linux kernel

How to mitigate CVE-2026-64252

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins