VYPR
High severity7.1NVD Advisory· Published May 6, 2026· Updated Jun 17, 2026

CVE-2026-43281

CVE-2026-43281

Description

In the Linux kernel, the following vulnerability has been resolved:

mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()

Although it is guided that #mbox-cells must be at least 1, there are many instances of #mbox-cells = <0>; in the device tree. If that is the case and the corresponding mailbox controller does not provide fw_xlate and of_xlate function pointers, fw_mbox_index_xlate()` will be used by default and out-of-bounds accesses could occur due to lack of bounds check in that function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

23

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.