CVE-2026-43274

medium Red Hat
Published: May 6, 2026 (8 days ago)
Last Modified: May 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's mailbox subsystem, specifically within the mchp-ipc-sbi component. This vulnerability involves an out-of-bounds access in the `mchp_ipc_get_cluster_aggr_irq()` function. The `cluster_cfg` array, which holds per-CPU configuration structures, was incorrectly indexed using `hartid`, which could exceed the array's bounds. This issue can lead to memory corruption within the kernel.

CWE

CWE-1285

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References