From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0F961322B6D for ; Mon, 8 Jun 2026 15:47:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780933668; cv=none; b=XlJ3blXMe/sJlwP/SpmoJ4FNP6KO3FrFQRBgIbW+GLujZM+qG7DtVAkTuzBUMI7WrvApu/DKYGxdSw0L0+NAb/FPjDkIGFInlyBQKEoibP3MNcHBPoSlqTB/Uwr5Ss2gg8MKOFpftzUzf7RlK+nYXTLuZtWAAkLogEVTWMxxCj0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780933668; c=relaxed/simple; bh=R96EnnbJ4ElGO13jgcfFn8HW73nRY80l+r629KVMJac=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Xvf2OgR8gn8tQz9980XLac/eSbpGffmnRWTwgjJy8a2hfWwZPCIa/6J+5THsL+UVbKgTrexjyiMPWrGYIOiCfThFCy3WoWMe5DmDL69qob3yE81yTLexFHVvImXoZ574chelxbQ1BJ6fC6u1Jwh0uL87ozi1dP16cKKx6cW2gRs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=nxs9IOFC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="nxs9IOFC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 18E151F00893; Mon, 8 Jun 2026 15:47:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1780933666; bh=gtfAChXZ0wJdhQSKU5RqR4Mf24seTY7sFsnTH0GLBRE=; h=From:To:Cc:Subject:Date:Reply-To; b=nxs9IOFCzmsRnFz7x3EiaOfmr8aGP3InALX3w6eF9l9zNOSZ/icXzakWzqXIXKfod ne/ocPxB5z02x3yNGORP/j0SfRLGRyqPUNJc3/x3ZGFHdtUqABwzgKmzHBP3l2CU4U AyNUg3lkxbh6SaUbQ2nuZjfuXUoRsy1kTZ0phH7w= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-46293: clk: microchip: mpfs-ccc: fix out of bounds access during output registration Date: Mon, 8 Jun 2026 17:46:01 +0200 Message-ID: <2026060857-CVE-2026-46293-b59c@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3190; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=xvq2E9gEWBE1Lbt2uLKIsZoowYG91VCKUqWFS0rwvjg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlqj7e+2fLEVGTnzGLRS2JL8ic+adarvblf3iJIIK32w W6HnxxBHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCRujsM8xPnT8uZ63gl0137 sf9Xkdxe7pZLWgxzOFbt7XBWz7dc/PHLb5/g6P8LPNbOAgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access during output registration UBSAN reported an out of bounds access during registration of the last two outputs. This out of bounds access occurs because space is only allocated in the hws array for two PLLs and the four output dividers that each has, but the defined IDs contain two DLLS and their two outputs each, which are not supported by the driver. The ID order is PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs by two while adding them to the array to avoid the problem. The Linux kernel CVE team has assigned CVE-2026-46293 to this issue. Affected and fixed versions =========================== Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 6.1.175 with commit 9ed9b580a814773482c0a4f1be045636e68cc109 Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 6.6.140 with commit 47bc7a03449c39805bc2665d3e57c73195d5bcf8 Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 6.12.88 with commit dbfcb09656cb30439577325c9dea2250203c2e3c Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 6.18.30 with commit a0780aeea166a7cf4706c45af4cadbb2a43a1fc9 Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 7.0.7 with commit f24efd415455b98a1f1cfc6071fe6fde71986706 Issue introduced in 6.1 with commit d39fb172760e426e0628f16b785c85e16d17bd5e and fixed in 7.1-rc1 with commit 2f7ae8ab6aa73daaf080d5332110357c29df9c36 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-46293 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/clk/microchip/clk-mpfs-ccc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109 https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8 https://git.kernel.org/stable/c/dbfcb09656cb30439577325c9dea2250203c2e3c https://git.kernel.org/stable/c/a0780aeea166a7cf4706c45af4cadbb2a43a1fc9 https://git.kernel.org/stable/c/f24efd415455b98a1f1cfc6071fe6fde71986706 https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36