Out-of-Bounds Memory Access in Linux Kernel's ARM SCPI Firmware
CVE-2026-98363
What is CVE-2026-98363?
The Linux kernel has identified a vulnerability related to the ARM SCPI firmware, which allows for an out-of-bounds memory access due to insufficient validation of the dynamic voltage and frequency scaling (DVFS) operating performance points (OPPs). The function 'scpi_dvfs_get_info()' previously rejected a zero OPP count but failed to appropriately discard larger out-of-range values received from the SCP firmware. As a result, an attempt to read more entries than the allotted limit in 'buf.opps[]' can lead to memory corruption or unexpected behaviors due to incorrectly sized OPP tables containing garbage values. The vulnerability stems from a missing upper bound check in the initial SCPI DVFS implementation. The fix involves validating both zero and out-of-bound counts in one consolidated check, thereby enhancing the firmware's resilience against improper input.
Affected Version(s)
Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa
Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa < 1aadbef648e92ca642125f188f99b0a26628e3ba
Linux 8cb7cf56c9fe5412de238465b27ef35b4d2801aa < 7daaa684097377b66b98a832de307688a7f3bbc7