-

CVE-2026-80640

cxl/fwctl: Fix __fortify_panic

In the Linux kernel, the following vulnerability has been resolved:

cxl/fwctl: Fix __fortify_panic

Fix a runtime assertion in cxlctl_get_supported_features(). Fortify
complains that it is potentially overflowing the entries array per
__counted_by_le(num_entries). Quiet the false positive by initializing
@num_entries earlier.

 memcpy: detected buffer overflow: 48 byte write of buffer size 0
 WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#7: fwctl/1398
 RIP: 0010:__fortify_report+0x50/0xa0
 Call Trace:
  __fortify_panic+0xd/0xf
  cxlctl_get_supported_features.cold+0x23/0x35 [cxl_core]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4d1c09cef2c244bd19467c016a3e56ba28ecc59d
Version < b8d15e85596ad8993d42e0703a9741961a2f03eb
Status affected
Version 4d1c09cef2c244bd19467c016a3e56ba28ecc59d
Version < 18c67ecc5dafe14055edcea53f36f4e31df1816b
Status affected
Version 4d1c09cef2c244bd19467c016a3e56ba28ecc59d
Version < 6c9d2e87df40d606f1c85143e9acb1ecff463d5e
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b8d15e85596ad8993d42e0703a9741961a2f03eb
https://git.kernel.org/stable/c/18c67ecc5dafe14055edcea53f36f4e31df1816b
https://git.kernel.org/stable/c/6c9d2e87df40d606f1c85143e9acb1ecff463d5e