CVE-2026-45994 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ibmasm: fix OOB reads in command_file_write due to missing size checks The command_file_write() handler allocates a kernel buffer of exactly count bytes and copies user data into it, but does not validate the buffer against the dot command protocol before passing it to get_dot_command_size() and get_dot_command_timeout(). Since both the allocation size (count) and the header fields (command_size, data_size) are independently user-controlled, an attacker can cause get_dot_command_size() to return a value exceeding the allocation, triggering OOB reads in get_dot_command_timeout() and an out-of-bounds memcpy_toio() that leaks kernel heap memory to the service processor. Fix with two guards: reject writes smaller than sizeof(struct dot_command_header) before allocation, then after copying user data reject commands where the buffer is smaller than the total size declared by the header (sizeof(header) + command_size + data_size). This ensures all subsequent header and payload field accesses stay within the buffer.
A vulnerability in the Linux kernel's ibmasm driver allows for out-of-bounds (OOB) reads in the command_file_write() handler. The issue arises because the handler allocates a kernel buffer of a specified size and copies user data into it without validating the buffer against the dot command protocol. This oversight enables an attacker to manipulate the header fields, causing the system to read beyond the allocated buffer and leak kernel heap memory to the service processor. The vulnerability has been addressed by implementing size checks to ensure that all data stays within the allocated buffer.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0eb09f737428e482a32a2e31e5e223f2b35a71d3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/44ee19422aa82a6847594866de7e5a31e4ef98b3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b8a574da5d7ea99b943f7a3458a17a1d95e8838 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a672682d39dd34e2b5ba4feb436723bed65125ff | kernel.org | Patch |
| https://git.kernel.org/stable/c/aefc1a97da17d8309974690c8a03e439a91ebb1c | kernel.org | Patch |
| https://git.kernel.org/stable/c/d0fb4d1dc43f8d5179917a2daaa82680993d4cdf | kernel.org | Patch |
| https://git.kernel.org/stable/c/d50e2019c9d7c433f56d9dff65703eb904aa1fb1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ee5737891464030a189837467df3b81a273718ad | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.12.1, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 2.6.12 - 2.6.12 rc2 2.6.12 rc3 2.6.12 rc4 2.6.12 rc5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |