← Back

CVE-2026-43281

nvd nist
Published: May 6, 2026Modified: Jun 1, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

In the Linux kernel, the following vulnerability has been resolved: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() Although it is guided that `#mbox-cells` must be at least 1, there are many instances of `#mbox-cells = <0>;` in the device tree. If that is the case and the corresponding mailbox controller does not provide `fw_xlate` and of_xlate` function pointers, `fw_mbox_index_xlate()` will be used by default and out-of-bounds accesses could occur due to lack of bounds check in that function.

Affected (12)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.18.1 to 6.1.167
From 6.13 to 6.18.16
From 6.19 to 6.19.6
From 6.2 to 6.6.130
From 6.7 to 6.12.77
Version 3.18
Version 3.18 rc2
Version 3.18 rc3
Version 3.18 rc4
Version 3.18 rc5
Version 3.18 rc6
Version 3.18 rc7

References (8)

Timeline

No history available yet.