PatchSiren cyber security CVE debrief
CVE-2026-23474 Linux CVE debrief
A buffer overflow vulnerability exists in the Linux kernel's RedBoot partition table parser within the MTD (Memory Technology Device) subsystem. The flaw occurs when parsing partition names where a memcmp() operation reads beyond the bounds of a dynamically allocated buffer. When CONFIG_FORTIFY_SOURCE is enabled with a recent compiler, this triggers a detected buffer overflow warning and kernel oops during boot. The vulnerability stems from calculating allocation size with strlen() but using memcmp() with a potentially larger comparison length. The fix replaces memcmp() with strcmp() to remain within bounds. This affects local attack vectors where an attacker with low privileges could potentially cause denial of service through crafted partition table data.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Embedded Linux developers, IoT device manufacturers, industrial control system operators, and organizations running Linux on hardware with RedBoot firmware and MTD flash storage. Particularly relevant for systems where local attackers may have low-privilege access to partition table data.
Technical summary
The vulnerability exists in drivers/mtd/parsers/redboot.c where partition name comparison uses memcmp() with a length derived from namelen field without proper bounds validation against the actual allocation size. The allocation uses strlen() on the source name, but namelen in the partition table could exceed this. With CONFIG_FORTIFY_SOURCE=y and modern compilers using __builtin_dynamic_object_size(), the out-of-bounds read is detected and triggers a kernel warning/oops. The fix replaces memcmp() with strcmp() which naturally terminates at null bytes, respecting allocation boundaries. Affected systems include embedded devices using RedBoot firmware with MTD flash storage, particularly those with CONFIG_MTD_REDBOOT_PARTS enabled.
Defensive priority
medium
Recommended defensive actions
- Apply kernel patches from stable branches: 5.10.253+, 5.15.203+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, or 6.19.10+
- Verify kernel configuration does not disable FORTIFY_SOURCE protections
- Monitor boot logs for RedBoot partition parsing warnings on embedded/MTD systems
- Review custom MTD partition table implementations for similar boundary issues
- Prioritize patching on systems using RedBoot firmware with MTD flash storage
Evidence notes
CVE description confirms buffer overflow in RedBoot partition table parser with FORTIFY_SOURCE detection. CVSS 5.5 (MEDIUM) with AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H vector indicates local attack, low complexity, low privileges required, no user interaction, with high availability impact. Multiple stable kernel patches provided across affected versions. NVD CPE criteria specify vulnerable version ranges from 2.6.12 through 6.19.9, with specific exclusions for patched versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23474 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23474
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23474 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23474
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ca235d11fc2fd8fce1dcd9d732dc780be0cde2de
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.