---
id: CVE-2026-46293
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: microchip: mpfs-ccc: fix out of bounds access during output registration

  UBSAN reported an out of bounds access during registration of the last
  two outputs
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: microchip: mpfs-ccc: fix out of bounds access during output registration

  UBSAN reported an out of bounds access during registration of the last
  two outputs. This …
severity: none
published: '2026-06-08'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46293'
references:
  - url: 'https://git.kernel.org/stable/c/2f7ae8ab6aa73daaf080d5332110357c29df9c36'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/47bc7a03449c39805bc2665d3e57c73195d5bcf8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9ed9b580a814773482c0a4f1be045636e68cc109'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a0780aeea166a7cf4706c45af4cadbb2a43a1fc9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dbfcb09656cb30439577325c9dea2250203c2e3c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f24efd415455b98a1f1cfc6071fe6fde71986706'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00126
epssPercentile: 0.02611
ingestedAt: '2026-07-07T18:42:24.303Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

clk: microchip: mpfs-ccc: fix out of bounds access during output registration

UBSAN reported an out of bounds access during registration of the last
two outputs. This out of bounds access occurs because space is only
allocated in the hws array for two PLLs and the four output dividers
that each has, but the defined IDs contain two DLLS and their two
outputs each, which are not supported by the driver. The ID order is
PLLs -> DLLs -> PLL outputs -> DLL outputs. Decrement the PLL output IDs
by two while adding them to the array to avoid the problem.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
