Description
In the Linux kernel, the following vulnerability has been resolved:

remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()

table->offset[i] is a u32 from firmware, but was stored into a signed
int. A crafted offset like 0xFFFFFFF0 becomes -16, placing hdr 16 bytes
before the table buffer. The subsequent avail check was bypassed
because the negative int was promoted to a large size_t in the
expression "table_sz - offset - sizeof(*hdr)", yielding a large positive
avail and letting the out-of-bounds hdr->type read proceed undetected.

Store the offset as u32 and validate it with unsigned comparisons before
any pointer arithmetic.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A kernel fault in remoteproc caused the client firmware to use a signed 32‑bit integer where an unsigned value was required. A crafted offset such as 0xFFFFFFF0 turns into -16, which the code then promotes to a large unsigned size_t during arithmetic. This permits the driver to read a header structure 16 bytes before the legitimate buffer, exposing kernel memory or crashing the driver. The fix stores the offset as an unsigned 32‑bit value and validates it with unsigned comparisons before any pointer calculation, eliminating the overflow path.

Affected Systems

All Linux kernel builds that include the remoteproc subsystem are impacted until they have applied the patch that introduced the unsigned handling. No specific vendor or version list is supplied, but any system executing kernel code prior to commit 0d385be8f199b349f325cf90584b47b6a044ea79 is vulnerable.

Risk and Exploitability

The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low to moderate exploitation probability. The attack requires a firmware image with a crafted signed offset for a device that loads firmware via remoteproc. An attacker could potentially cause a crash or read sensitive kernel data, but would need to supply malicious firmware to the target. Overall risk remains relatively low, yet the attack surface exists in embedded or IoT devices where firmware updates are performed without stringent validation.

Generated by OpenCVE AI on September 19, 2026 at 04:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that corrects the signed offset handling (commit 0d385be8f199b349f325cf90584b47b6a044ea79).
  • If a kernel update is unavailable, restrict firmware updates to authenticated and integrity‑checked sources to prevent the injection of malicious offsets.
  • Increase kernel logging or monitoring for assertion failures or unusual memory accesses that may indicate an attempted out‑of‑bounds read during remoteproc operations.

Generated by OpenCVE AI on September 19, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() table->offset[i] is a u32 from firmware, but was stored into a signed int. A crafted offset like 0xFFFFFFF0 becomes -16, placing hdr 16 bytes before the table buffer. The subsequent avail check was bypassed because the negative int was promoted to a large size_t in the expression "table_sz - offset - sizeof(*hdr)", yielding a large positive avail and letting the out-of-bounds hdr->type read proceed undetected. Store the offset as u32 and validate it with unsigned comparisons before any pointer arithmetic.
Title remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:33.568Z

Reserved: 2026-09-11T19:38:34.801Z

Link: CVE-2026-90314

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:29.203

Modified: 2026-09-17T17:17:29.203

Link: CVE-2026-90314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses