CVE-2026-72156: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

fpga: microchip-spi: fix zero headersize OOB read in mpfopsparseheader()

mpfopsparseheader() reads headersize from the bitstream at MPFHEADERSIZEOFFSET (24). When headersize is zero, the expression (buf + headersize - 1) reads one byte before the buffer start.

Since initialheadersize is set to 71 in mpfops, the fpga-mgr core guarantees the buffer is large enough to reach MPFHEADERSIZEOFFSET. The only real gap is the zero headersize case, which cannot be resolved by providing a larger buffer, so return -EINVAL.

Affected Software

1 affected component
Linux Kernel

Event History

Aug 15, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
Description
Data Sourced
via NVD·06:21 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72156?

CVE-2026-72156 has a severity score of 15, indicating a critical risk.

2

How do I fix CVE-2026-72156?

To fix CVE-2026-72156, ensure that you update your Linux kernel to a version that contains the patch for this vulnerability.

3

What does CVE-2026-72156 affect?

CVE-2026-72156 affects the FPGA subsystem in the Linux kernel, specifically the microchip-spi component.

4

Can CVE-2026-72156 lead to data leakage?

Yes, CVE-2026-72156 can potentially lead to an out-of-bounds read which may expose sensitive data.

5

How was CVE-2026-72156 discovered?

CVE-2026-72156 was discovered through code review of the mpf_ops_parse_header() function within the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203