Out-of-bounds write in Linux kernel - CVE-2026-80723
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in fdt_scan_reserved_mem() when processing device tree reserved-memory subnodes during boot. A local attacker can supply a device tree with more than MAX_RESERVED_REGIONS dynamically-placed regions to cause a denial of service.
Exploitation requires control over the device tree used at boot.