Bug 2486474 (CVE-2026-46293) - CVE-2026-46293 kernel: clk: microchip: mpfs-ccc: fix out of bounds access during output registration
Summary: CVE-2026-46293 kernel: clk: microchip: mpfs-ccc: fix out of bounds access dur...
Keywords:
Status: NEW
Alias: CVE-2026-46293
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-08 17:03 UTC by OSIDB Bzimport
Modified: 2026-06-08 19:21 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-08 17:03:56 UTC
In the Linux kernel, the following vulnerability has been resolved:

clk: microchip: mpfs-ccc: fix out of bounds access during output registration

UBSAN reported an out of bounds access during registration of the last
two outputs. This out of bounds access occurs because space is only
allocated in the hws array for two PLLs and the four output dividers
that each has, but the defined IDs contain two DLLS and their two
outputs each, which are not supported by the driver. The ID order is
PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs
by two while adding them to the array to avoid the problem.


Note You need to log in before you can comment on or make changes to this bug.