Junglewise Threat Intelligence

CVE-2026-80745: Linux kernel FP9931 regulator out-of-bounds read

CVE-2026-80745 · Severity: high · CVSS 8.4 · Published 2026-09-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The FP9931 power management IC driver in the Linux kernel contains a buffer overflow vulnerability in its voltage lookup table. Devices using this regulator could experience undefined behavior, system crashes, or memory disclosure when the regulator is accessed with certain selector values. This affects embedded systems and devices that rely on this regulator for power management.

Technical details

The VPOSNEG_table[] array in the fp9931 regulator driver has two issues: (1) a duplicate entry causing all subsequent mappings to be shifted by one position, and (2) the table contains only 41 entries instead of the required 64 (0x00–0x3F), leading to out-of-bounds read access when selector values 0x29–0x3F are used. The root cause is incorrect table initialization that does not match the FP9931 datasheet specifications. An attacker or malicious userspace code with access to regulator control can trigger out-of-bounds memory reads by selecting invalid voltage levels. The fix removes the duplicate 7.04V entry and appends 23 missing clamped entries to bring the table to 64 entries.

Affected products

  • Linux Linux kernel all versions with fp9931 regulator driver

Timeline

  • 2026-09-03: disclosed: CVE-2026-80745 published
  • 2026-07-31: patched: Fix merged to kernel mainline by Mark Brown

References

Related threats