Improper Validation of Array Index in Linux kernel - CVE-2026-92478

 

Improper Validation of Array Index in Linux kernel - CVE-2026-92478

Published: September 18, 2026


Vulnerability identifier: #VU151041
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92478
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to access memory out of bounds.

The vulnerability exists due to improper validation of array indices in the UFS core TX equalization code when processing invalid connected RX or TX lane counts. An attacker with physical access can cause invalid connected lane counts to be processed to access memory out of bounds.


Affected software

Linux kernel

How to mitigate CVE-2026-92478

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins