Junglewise Threat Intelligence

CVE-2026-43175: Linux Kernel out-of-bounds write in Renesas PCIe clock driver

CVE-2026-43175 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Renesas PCIe clock driver could cause system instability or crashes. The issue occurs when using specific hardware (9FGV0841) that has more outputs than the driver was designed to handle, leading to memory corruption. This typically results in a system crash during power management events like suspending or when the driver is removed.

Technical details

An out-of-bounds write vulnerability exists in the Renesas PCIe clock driver (clk-renesas-pcie.c) within the Linux kernel. The driver's rs9_driver_data structure originally reserved only 4 slots for clk_hw pointers, but the 9FGV0841 chip supports 8 outputs. When the driver registers these 8 outputs, it writes beyond the bounds of the clk_dif array, corrupting adjacent structure members and memory. While the corruption may not cause an immediate crash, it reliably triggers a kernel panic during driver unbinding or system suspend. The fix involves increasing the array size to 8 to accommodate the maximum supported output count.

Affected products

  • Linux Linux Kernel 6.8 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-01-22: other: Patch authored
  • 2026-05-06: disclosed: CVE published
  • 2026-05-12: advisory: NVD analysis completed

References

Related threats