CVE-2026-80624

Source
https://cve.org/CVERecord?id=CVE-2026-80624
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80624.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80624
Downstream
Published
2026-08-28T06:48:42.983Z
Modified
2026-08-30T03:48:22.921970310Z
Summary
mfd: cs42l43: Sanity check firmware size
Details

In the Linux kernel, the following vulnerability has been resolved:

mfd: cs42l43: Sanity check firmware size

Currently the code checks if a firmware was received, however it does not verify that the firmware size is larger than the firmware header. As the firmware pointer is dereferenced as a pointer to the header structure this could lead to an out of bounds memory access. Add the missing check.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80624.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ace6d14481386ec6c1b63cc2b24c71433a583dc2
Fixed
2ce02059ceb6311a33026b62e6e4dc4ed22a3aef
Fixed
197a4c54d8a94fe2fb7829661b29f0859c10feb5
Fixed
d35e4032f16d7621468c8b56816e7935ebf590a7
Fixed
17d79248b4f370663f9d351409a130fc1ed9416d
Fixed
b6ef1a74b3ec254f87a6a3c554fe8f8083ebd37c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80624.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80624.json"