Answer in brief
CVE-2026-90314 records a Unknown severity vulnerability in remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <0d385be8f199b349f325cf90584b47b6a044ea79 || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <cc85e0d3d3333fd5fd2d50c9a4578d209d7f2564 || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <6a01ad25aa4f3a02153cf1d112cb9b65865cd5d8 || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <c82241a9454b2d30d53b50884f94b7972ba44a5e || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <bc4940793aaa16a9cf90063b11d6926f8014a1b7 || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <6fd220604f06c746760183df74b07384c3fdd660 || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <6282d47b24b0c98d08d02807d676a7f67b4c052e || >=fd2c15ec1dd3c2fdfc6ff03bb9644da9d530e3b9 <bb840ea69347aff7bde5a208e7b5b180669a7656 | 0d385be8f199b349f325cf90584b47b6a044ea79, cc85e0d3d3333fd5fd2d50c9a4578d209d7f2564, 6a01ad25aa4f3a02153cf1d112cb9b65865cd5d8, c82241a9454b2d30d53b50884f94b7972ba44a5e, bc4940793aaa16a9cf90063b11d6926f8014a1b7, 6fd220604f06c746760183df74b07384c3fdd660, 6282d47b24b0c98d08d02807d676a7f67b4c052e, bb840ea69347aff7bde5a208e7b5b180669a7656 |
| Linux/Linuxgeneric | 3.4 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() table->offset[i] is a u32 from firmware, but was stored into a signed int. A crafted offset like 0xFFFFFFF0 becomes -16, placing hdr 16 bytes before the table buffer. The subsequent avail check was bypassed because the negative int was promoted to a large size_t in the expression "table_sz - offset - sizeof(*hdr)", yielding a large positive avail and letting the out-of-bounds hdr->type read proceed undetected. Store the offset as u32 and validate it with unsigned comparisons before any pointer arithmetic.
Quoted source text, attributed separately from HOL analysis.