CVE-2026-74271

high

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: core: fix supplied_from allocations If dts property power-supplies has multiple values, then accessing to psy->supplied_from[i-1] in __power_supply_populate_supplied_from will overrun supplied_from array.

References

https://git.kernel.org/stable/c/fefc9dad30d545be288d50a0b10d00465015fcfe

https://git.kernel.org/stable/c/d0503357653ee62188987a26baa2d7f3689f367e

https://git.kernel.org/stable/c/ba61aed9a34671222d1149acfc2f0179a9ce7e80

https://git.kernel.org/stable/c/ae55e4bf18ee0c4c170797dd65e17dbdf644fcf2

https://git.kernel.org/stable/c/23a29ee1d9de38b7d6226b27653bc736b28ff05a

https://git.kernel.org/stable/c/14357ba006e1586e4b4e809c074b21baf0aa4c4b

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00205