Junglewise Threat Intelligence

CVE-2026-46022: Linux Kernel ibmasm OOB MMIO read in ibmasm_handle_mouse_interrupt

CVE-2026-46022 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IBM Advanced System Management (ibmasm) driver could allow a compromised service processor to crash the host system. The driver, which manages communication with IBM service processors, fails to validate data received from the hardware. This can lead to the system attempting to read memory from invalid locations, resulting in a system crash (machine check exception).

Technical details

An out-of-bounds (OOB) Memory-Mapped I/O (MMIO) read exists in the ibmasm_handle_mouse_interrupt() function within drivers/misc/ibmasm/remote.c. The vulnerability is caused by a lack of bounds checking on the reader and writer indices retrieved from the hardware via get_queue_reader() and get_queue_writer(). These raw values are passed to get_queue_entry(), which calculates an MMIO address that is subsequently used in memcpy_fromio(). A compromised service processor can provide indices exceeding REMOTE_QUEUE_SIZE (60), causing the kernel to read from unintended device registers or outside the PCI BAR mapping entirely, triggering a machine check exception. The fix implements bounds checking at the start of the interrupt loop and resets the reader register if an invalid index is detected.

Affected products

  • Linux Linux Kernel All versions prior to the May 2026 patches

Timeline

  • 2026-03-08: other: Vulnerability reported by researcher
  • 2026-05-07: patched: Patches committed to stable kernel trees
  • 2026-05-27: advisory: CVE-2026-46022 published

References