CVE Database
/

CVE-2026-43145

Back to search

CVE-2026-43145

Published: May 6, 2026

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: remoteproc: imx_rproc: Fix invalid loaded resource table detection imx_rproc_elf_find_loaded_rsc_table() may incorrectly report a loaded resource table even when the current firmware does not provide one. When the device tree contains a "rsc-table" entry, priv->rsc_table is non-NULL and denotes where a resource table would be located if one is present in memory. However, when the current firmware has no resource table, rproc->table_ptr is NULL. The function still returns priv->rsc_table, and the remoteproc core interprets this as a valid loaded resource table. Fix this by returning NULL from imx_rproc_elf_find_loaded_rsc_table() when there is no resource table for the current firmware (i.e. when rproc->table_ptr is NULL). This aligns the function's semantics with the remoteproc core: a loaded resource table is only reported when a valid table_ptr exists. With this change, starting firmware without a resource table no longer triggers a crash.

VendorProductVersions

Linux

Linux

affected
64f2ca5ce97111a364a18c31772eb46c79e8b772 - < 91baf24d972ea3c04a75dd18821c03d223c0dbc0
affected
1d750606fedcdff7886f35a558c51b05ce2680a6 - < fcec79b6a3649ae7b1f659267602ca402c240d6e
affected
7fb5f957213bc7268bac449f8bfe95967c9f3f3b - < 9bd98d088f47153a81a6ec8162b4415c64aa7f39
affected
e954a1bd16102abc800629f9900715d8ec4c3130 - < 65379adf7d231c930572db45933ff4538f4c5128
affected
e954a1bd16102abc800629f9900715d8ec4c3130 - < 500778df9e4c313190368908ff40c23948508e97

+7 more versions

Linux

Linux

affected
6.12
unaffected
0 - < 6.12
unaffected
5.15.202 - <= 5.15.*
unaffected
6.1.165 - <= 6.1.*
unaffected
6.6.128 - <= 6.6.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now