Executive brief
A vulnerability in the Linux kernel's mailbox subsystem could allow a local attacker to cause a system crash or potentially access sensitive memory. The mailbox component is responsible for communication between different processors or hardware modules within a system. This issue occurs when certain hardware configuration files (device trees) contain unexpected values, leading to an out-of-bounds memory access.
Technical details
The vulnerability is a CWE-125 (Out-of-bounds Read) located in the mailbox framework, specifically within the fw_mbox_index_xlate() and of_mbox_index_xlate() functions in drivers/mailbox/mailbox.c. While documentation specifies that '#mbox-cells' should be at least 1, some device trees use a value of 0. When a mailbox controller lacks custom translation pointers (fw_xlate or of_xlate), the kernel falls back to default functions that fail to validate the number of arguments (nargs/args_count) before accessing the args array. A local attacker with the ability to trigger mailbox channel requests could exploit this to read out-of-bounds kernel memory or cause a denial-of-service (kernel oops). Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.18.1 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.77, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: advisory: Initial NVD publication
- 2026-03-13: patched: Fix committed to stable kernel tree
References
- https://git.kernel.org/stable/c/01d9a8c2615d436b2b30c19c1afe9fcd5726ff6d
- https://git.kernel.org/stable/c/2662ed331a69c0b551f78af58f12eb629a89a36f
- https://git.kernel.org/stable/c/2c7ff651ec6b660c7c96a36db9328b3232f555d8
- https://git.kernel.org/stable/c/31c4c67dec3362094a6747a171a4848e98542265
- https://git.kernel.org/stable/c/4caae8168d1b808c7d4ff481295292e3f97f90fb
- https://git.kernel.org/stable/c/ec0874447895b994182a962d2fee9ef075de5efd
- https://git.kernel.org/stable/c/f50b39fd7c72a8734153644ee945ca0d8b2e65ab