CVE-2026-46022 Details
Description
In the Linux kernel, the following vulnerability has been resolved: misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() ibmasm_handle_mouse_interrupt() performs an out-of-bounds MMIO read when the queue reader or writer index from hardware exceeds REMOTE_QUEUE_SIZE (60). A compromised service processor can trigger this by writing an out-of-range value to the reader or writer MMIO register before asserting an interrupt. Since writer is re-read from hardware on every loop iteration, it can also be set to an out-of-range value after the loop has already started. The root cause is that get_queue_reader() and get_queue_writer() return raw readl() values that are passed directly into get_queue_entry(), which computes: queue_begin + reader * sizeof(struct remote_input) with no bounds check. This unchecked MMIO address is then passed to memcpy_fromio(), reading 8 bytes from unintended device registers. For sufficiently large values the address falls outside the PCI BAR mapping entirely, triggering a machine check exception. Fix by checking both indices against REMOTE_QUEUE_SIZE at the top of the loop body, before any call to get_queue_entry(). On an out-of-range value, reset the reader register to 0 via set_queue_reader() before breaking, so that normal queue operation can resume if the corrupted hardware state is transient.
A vulnerability in the Linux kernel's ibmasm driver has been identified, where the function ibmasm_handle_mouse_interrupt() performs an out-of-bounds memory-mapped I/O (MMIO) read. This issue occurs when the queue reader or writer index from the hardware exceeds the defined REMOTE_QUEUE_SIZE of 60. A compromised service processor can exploit this by writing an out-of-range value to the MMIO register before triggering an interrupt. The unchecked index values are directly used to calculate the MMIO address, which, if improperly set, can lead to reading unintended device registers. In severe cases, the erroneous address may fall outside the PCI BAR mapping, causing a machine check exception.
The vulnerability has been addressed by adding bounds checks to ensure that the reader and writer indices do not exceed the REMOTE_QUEUE_SIZE. This fix has been implemented in the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/07c4f18b303106e6b24492c12b95d48a4b985841 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1ca75f6b74ec7f685464e5745ecfcf3a76d284e9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/22a16d3eafee92a165c756081587c95850127107 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4b6e6ead556734bdc14024c5f837132b1e7a4b84 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6f6ecc9153df176e956d0664b56f93080b0a45f0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bac8643486f854dd53af9b23aea7dbbd9b7c1865 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f7e5b4eefd7be3e09f8bd5fee63ed478fd7446ab | kernel.org | Patch |
| https://git.kernel.org/stable/c/fc7e9a74e32299d7e93e178ca482a0b59ef1595b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.13, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |