CVE-2026-80723

Updated on 28 Aug 2026

Severity

8.4 High severity

Details

CVSS score
8.4
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

of: reserved_mem: prevent OOB when too many dynamic regions are defined

On boot, fdt_scan_reserved_mem() saves each dynamically-placed /reserved-memory subnode into a local array of size MAX_RESERVED_REGIONS.

If the device tree defines more than MAX_RESERVED_REGIONS dynamically-placed regions, fdt_scan_reserved_mem() writes past the end of the local array.

Add a bounds check that logs an error and skips the excess regions, restoring the original behavior.

Details

Affected product:
Debian 10 ELS
Affected packages:
linux @ 4.19.0

Fixes