CVE-2026-72156
fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
Description
In the Linux kernel, the following vulnerability has been resolved: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() mpf_ops_parse_header() reads header_size from the bitstream at MPF_HEADER_SIZE_OFFSET (24). When header_size is zero, the expression *(buf + header_size - 1) reads one byte before the buffer start. Since initial_header_size is set to 71 in mpf_ops, the fpga-mgr core guarantees the buffer is large enough to reach MPF_HEADER_SIZE_OFFSET. The only real gap is the zero header_size case, which cannot be resolved by providing a larger buffer, so return -EINVAL.
INFO
Published Date :
Aug. 15, 2026, 6:21 a.m.
Last Modified :
Aug. 17, 2026, 6:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Apply the provided Linux kernel patch.
- Update the affected Linux kernel version.
- Review header size validation logic.
- Test for correct buffer handling.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72156.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72156 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72156
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72156 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72156 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'e45ec24d8e986d79a8e07f49a816c414ad283622', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '0d3766fecd9b2db39a18b48021c15c522997ec25', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '3da8eaf5469eda2353b72038d644fabddb848ce1', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '43a1974da6bc7ce8f4d1dc1d03d56997428c29c3', 'versionType': 'git'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'e45ec24d8e986d79a8e07f49a816c414ad283622', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '0d3766fecd9b2db39a18b48021c15c522997ec25', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '3da8eaf5469eda2353b72038d644fabddb848ce1', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '43a1974da6bc7ce8f4d1dc1d03d56997428c29c3', 'versionType': 'git'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'e45ec24d8e986d79a8e07f49a816c414ad283622', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '0d3766fecd9b2db39a18b48021c15c522997ec25', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': 'c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '3da8eaf5469eda2353b72038d644fabddb848ce1', 'versionType': 'git'}, {'status': 'affected', 'version': '5f8d4a9008307e0bf210906948953386935d361c', 'lessThan': '43a1974da6bc7ce8f4d1dc1d03d56997428c29c3', 'versionType': 'git'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/fpga/microchip-spi.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() mpf_ops_parse_header() reads header_size from the bitstream at MPF_HEADER_SIZE_OFFSET (24). When header_size is zero, the expression *(buf + header_size - 1) reads one byte before the buffer start. Since initial_header_size is set to 71 in mpf_ops, the fpga-mgr core guarantees the buffer is large enough to reach MPF_HEADER_SIZE_OFFSET. The only real gap is the zero header_size case, which cannot be resolved by providing a larger buffer, so return -EINVAL. Added Reference https://git.kernel.org/stable/c/0d3766fecd9b2db39a18b48021c15c522997ec25 Added Reference https://git.kernel.org/stable/c/3da8eaf5469eda2353b72038d644fabddb848ce1 Added Reference https://git.kernel.org/stable/c/43a1974da6bc7ce8f4d1dc1d03d56997428c29c3 Added Reference https://git.kernel.org/stable/c/a1baee24df72ec8fd1d6925c1d5162ffff4ee3bf Added Reference https://git.kernel.org/stable/c/c9ef79e34bc1eac4fd59051e5c7b96a74e59d46f Added Reference https://git.kernel.org/stable/c/e45ec24d8e986d79a8e07f49a816c414ad283622