SB20260918170 - Integer underflow in Linux kernel mtd driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-93048)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a kernel warning.
The vulnerability exists due to integer underflow in mtd_add_partition() when processing BLKPG ioctl requests on NAND devices. A local user can pass MTDPART_OFS_RETAIN (-3) as a partition offset to trigger a kernel warning.
Depending on the size calculation, an empty disabled partition can be created.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/181c1bff940e7d3e34ca485d37e3cdbfe409203c
- https://git.kernel.org/stable/c/398aca2f90122d5abbabff1079deaeb885fe9e40
- https://git.kernel.org/stable/c/6aaab2ace3f7b55733d904e5549acf8405f03642
- https://git.kernel.org/stable/c/701c3ae7273e1adc20db5d97c42e0139b479f16b
- https://git.kernel.org/stable/c/a536eb57be58442b19398b2783071007ecfb1735
- https://git.kernel.org/stable/c/b759d5bb6265419344ee9729fd0dc07ad85719d8
- https://git.kernel.org/stable/c/c645f6dd1af2ecc70fd3578e141f2f71fa9e4eff
- https://git.kernel.org/stable/c/e204e5c49a012f99638633fdbd773e3c86260053