CVE-2026-80624 PUBLISHED

mfd: cs42l43: Sanity check firmware size

Assigner: Linux
Reserved: 26.08.2026 Published: 28.08.2026 Updated: 28.08.2026

In the Linux kernel, the following vulnerability has been resolved:

mfd: cs42l43: Sanity check firmware size

Currently the code checks if a firmware was received, however it does not verify that the firmware size is larger than the firmware header. As the firmware pointer is dereferenced as a pointer to the header structure this could lead to an out of bounds memory access. Add the missing check.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from ace6d14481386ec6c1b63cc2b24c71433a583dc2 to 2ce02059ceb6311a33026b62e6e4dc4ed22a3aef (excl.)
  • affected from ace6d14481386ec6c1b63cc2b24c71433a583dc2 to 197a4c54d8a94fe2fb7829661b29f0859c10feb5 (excl.)
  • affected from ace6d14481386ec6c1b63cc2b24c71433a583dc2 to d35e4032f16d7621468c8b56816e7935ebf590a7 (excl.)
  • affected from ace6d14481386ec6c1b63cc2b24c71433a583dc2 to 17d79248b4f370663f9d351409a130fc1ed9416d (excl.)
  • affected from ace6d14481386ec6c1b63cc2b24c71433a583dc2 to b6ef1a74b3ec254f87a6a3c554fe8f8083ebd37c (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.6 is affected
  • unaffected from 0 to 6.6 (excl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.97 to 6.12.* (incl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References