PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23474 Linux CVE debrief

A buffer overflow vulnerability exists in the Linux kernel's RedBoot partition table parser within the MTD (Memory Technology Device) subsystem. The flaw occurs when parsing partition names where a memcmp() operation reads beyond the bounds of a dynamically allocated buffer. When CONFIG_FORTIFY_SOURCE is enabled with a recent compiler, this triggers a detected buffer overflow warning and kernel oops during boot. The vulnerability stems from calculating allocation size with strlen() but using memcmp() with a potentially larger comparison length. The fix replaces memcmp() with strcmp() to remain within bounds. This affects local attack vectors where an attacker with low privileges could potentially cause denial of service through crafted partition table data.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Embedded Linux developers, IoT device manufacturers, industrial control system operators, and organizations running Linux on hardware with RedBoot firmware and MTD flash storage. Particularly relevant for systems where local attackers may have low-privilege access to partition table data.

Technical summary

The vulnerability exists in drivers/mtd/parsers/redboot.c where partition name comparison uses memcmp() with a length derived from namelen field without proper bounds validation against the actual allocation size. The allocation uses strlen() on the source name, but namelen in the partition table could exceed this. With CONFIG_FORTIFY_SOURCE=y and modern compilers using __builtin_dynamic_object_size(), the out-of-bounds read is detected and triggers a kernel warning/oops. The fix replaces memcmp() with strcmp() which naturally terminates at null bytes, respecting allocation boundaries. Affected systems include embedded devices using RedBoot firmware with MTD flash storage, particularly those with CONFIG_MTD_REDBOOT_PARTS enabled.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel patches from stable branches: 5.10.253+, 5.15.203+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, or 6.19.10+
  • Verify kernel configuration does not disable FORTIFY_SOURCE protections
  • Monitor boot logs for RedBoot partition parsing warnings on embedded/MTD systems
  • Review custom MTD partition table implementations for similar boundary issues
  • Prioritize patching on systems using RedBoot firmware with MTD flash storage

Evidence notes

CVE description confirms buffer overflow in RedBoot partition table parser with FORTIFY_SOURCE detection. CVSS 5.5 (MEDIUM) with AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H vector indicates local attack, low complexity, low privileges required, no user interaction, with high availability impact. Multiple stable kernel patches provided across affected versions. NVD CPE criteria specify vulnerable version ranges from 2.6.12 through 6.19.9, with specific exclusions for patched versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23474 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23474

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23474 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23474

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0b08be5aca212a99f8ba786fee4922feac08002c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2025b2d1f9d5cad6ea6fe85654c6c41297c3130b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/75a4d8cfe7784f909b3bd69325abac8e04ecb385

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8e2f8020270af7777d49c2e7132260983e4fc566

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c4054ad2d8bff4e8e937cd4a1d1a04c1e8f77a2c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ca235d11fc2fd8fce1dcd9d732dc780be0cde2de

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d8570211a2b1ec886a462daa0be4e9983ac768bb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.