Executive brief
The Linux kernel's Microchip FPGA manager driver processes firmware bitstreams for FPGA configuration. A malformed bitstream with a zero header size value causes the driver to read memory before the buffer start, potentially exposing sensitive kernel memory or causing a crash during FPGA programming operations.
Technical details
The vulnerability is an out-of-bounds (OOB) read in the mpf_ops_parse_header() function within drivers/fpga/microchip-spi.c. When parsing a FPGA bitstream, the function reads a header_size value from the bitstream at a fixed offset (24 bytes). If this value is zero, the subsequent pointer arithmetic *(buf + header_size - 1) attempts to dereference one byte before the buffer start. Although the fpga-mgr core guarantees an initial 71-byte buffer, this specific zero-value case creates a gap. The fix adds a validation check: if header_size is zero, the function returns -EINVAL to reject the malformed bitstream. Attack vector requires ability to provide a crafted bitstream to the FPGA manager (local or privileged access typically required).
Affected products
- Linux Linux kernel multiple versions prior to fix commit 43a1974da6bc7ce8f4d1dc1d03d56997428c29c3
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched: Fix committed upstream; backported to stable branches