CVE-2026-46293

Linux kernel (GCP) vulnerabilities

Beschreibung

Im Linux-Kernel wurde folgende Schwachstelle behoben: clk: microchip: mpfs-ccc: Behebung des Zugriffs außerhalb der Grenzen während der Ausgabe-Registrierung UBSAN meldete einen Zugriff außerhalb der Grenzen während der Registrierung der letzten zwei Ausgaben. Dieser Zugriff außerhalb der Grenzen tritt auf, weil im hws-Array nur Platz für zwei PLLs und die vier Ausgabeteiler, die jeder hat, reserviert ist, obwohl die definierten IDs zwei DLLs und deren jeweils zwei Ausgaben enthalten, die vom Treiber nicht unterstützt werden. Die ID-Reihenfolge lautet: PLLs -> DLLs -> PLL-Ausgaben -> DLL-Ausgaben. Verringern Sie die IDs der PLL-Ausgaben um zwei, während sie dem Array hinzugefügt werden, um das Problem zu vermeiden.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.1
Quelle: nvd-v3
2.6 %
Niedrig — CVE gehört zu den unteren 10 % der heute bewerteten CVEs.
0.1 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-07 09:05 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-23 08:10 UTC· nvd@nist.gov
    • Translation: Title: Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: clk: microchip: mpfs-ccc: corregir el acceso fuera de límites durante el registro de salida UBSAN informó un acceso fuera de límites durante el registro de las dos últimas salidas. Este acceso fuera de límites ocurre porque solo se asigna espacio en el array hws para dos PLLs y los cuatro divisores de salida que cada uno tiene, pero los IDs definidos contienen dos DLLS y sus dos salidas cada uno, que no son soportados por el controlador. El orden de los IDs es PLLs -> DLLs -> salidas de PLL -> salidas de DLL. Decrementar los IDs de salida de PLL en dos mientras se añaden al array para evitar el problema.
  2. New CVE Received2026-06-08 17:16 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Description: In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access during output registration UBSAN reported an out of bounds access during registration of the last two outputs. This out of bounds access occurs because space is only allocated in the hws array for two PLLs and the four output dividers that each has, but the defined IDs contain two DLLS and their two outputs each, which are not supported by the driver. The ID order is PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs by two while adding them to the array to avoid the problem.
    • Reference: https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36
    • Reference: https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8
    • Reference: https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / linux-aws-6.8jammy

  • linux

    ubuntu / linux-azureresolute

  • linux

    ubuntu / linux-azuretrusty

  • linux

    ubuntu / linux-azurexenial

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-5.4bionic

  • linux

    ubuntu / linux-azure-fdenoble

  • linux

    ubuntu / linux-azure-fderesolute

  • linux

    ubuntu / linux-azure-fde-6.8jammy

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-azure-fipsfocal

  • linux

    ubuntu / linux-azure-fipsnoble

  • linux

    ubuntu / linux-fipsjammy

  • linux

    ubuntu / linux-gcp-7.0noble

  • linux

    ubuntu / linux-gkejammy

  • linux

    ubuntu / linux-nvidia-tegranoble

  • linux

    ubuntu / linux-raspinoble

  • linux

    ubuntu / linux-raspi-realtimenoble

  • linux

    linux / linux_kernel2.6.12

  • linux

    linux / linux_kernel2.6.15

Quellen & Referenzen

Verknüpfte CVEs

1392 weitere CVEs anzeigen

Verknüpfte Empfehlungen

IDCVE-2026-46293
Linux kernel (GCP) vulnerabilities — CVE-2026-46293 | NEOSEC Intel