SB20260918239 - Improper Validation of Array Index in Linux kernel ufs core driver



SB20260918239 - Improper Validation of Array Index in Linux kernel ufs core driver

Published: September 18, 2026

Security Bulletin ID SB20260918239
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Array Index (CVE-ID: CVE-2026-92478)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to access memory out of bounds.

The vulnerability exists due to improper validation of array indices in the UFS core TX equalization code when processing invalid connected RX or TX lane counts. An attacker with physical access can cause invalid connected lane counts to be processed to access memory out of bounds.


Remediation

Install update from vendor's website.