Executive brief
The Linux kernel's power supply subsystem contains a buffer overflow vulnerability in the supplied_from allocation logic. When a device tree property specifies multiple power supplies, the code incorrectly allocates and accesses the array, potentially leading to memory corruption. This could affect any Linux system with multiple power supplies configured in device tree, risking kernel crashes or unexpected behavior.
Technical details
This is an array bounds overflow in drivers/power/supply/power_supply_core.c within the __power_supply_populate_supplied_from function. When the device tree property "power-supplies" contains multiple values, the vulnerable code allocates insufficient memory (only one pointer instead of cnt-1 pointers) for the supplied_from array, then attempts to write beyond allocated bounds. The fix changes from a devm_kzalloc + devm_kcalloc two-step allocation to a single devm_kcalloc that correctly sizes the array for cnt-1 supplies. The vulnerability requires local access and is triggered only when device tree power supply configurations have multiple entries. The patch was authored by Lucas Tsai and merged in upstream commit ba61aed9a34671222d1149acfc2f0179a9ce7e80.
Affected products
- Linux Linux Kernel Multiple versions prior to fix (2.6.11 through 6.x series)
Timeline
- 2026-08-15: disclosed: CVE-2026-74271 published
- 2026-06-09: patched: Patch authored by Lucas Tsai
- 2026-07-24: patched: Patch merged to stable kernel tree by Greg Kroah-Hartman