SB20260918239 - Improper Validation of Array Index in Linux kernel ufs core driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Array Index (CVE-ID: CVE-2026-92478)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to access memory out of bounds.
The vulnerability exists due to improper validation of array indices in the UFS core TX equalization code when processing invalid connected RX or TX lane counts. An attacker with physical access can cause invalid connected lane counts to be processed to access memory out of bounds.
Remediation
Install update from vendor's website.