CVE-2026-46190

Updated on 28 May 2026

Severity

7.1 High severity

Details

CVSS score
7.1

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() Sashiko noticed an out-of-bounds read [1]. In spi_nor_params_show(), the snor_f_names array is passed to spi_nor_print_flags() using sizeof(snor_f_names). Since snor_f_names is an array of pointers, sizeof() returns the total number of bytes occupied by the pointers (element_count * sizeof(void *)) rather than the element count itself. On 64-bit systems, this makes the passed length 8x larger than intended. Inside spi_nor_print_flags(), the ’names_len’ argument is used to bounds-check the ’names’ array access. An out-of-bounds read occurs if a flag bit is set that exceeds the array’s actual element count but is within the inflated byte-size count. Correct this by using ARRAY_SIZE() to pass the actual number of string pointers in the array. A flaw was found in the Linux kernel’s Memory Technology Device (MTD) SPI-NOR debugfs component. An out-of-bounds read vulnerability exists in the spi_nor_params_show() function due to an incorrect calculation of an array’s size. This error allows a local attacker to read memory outside of the intended buffer, which could lead to information disclosure or system instability.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 12 Planned
Debian 13 Released
7 kernels
  • 6.12.85-1
  • 6.12.86-1
  • 6.12.73-1
  • 6.12.63-1
  • 6.12.69-1
  • 6.12.74-1
  • 6.12.74-2
Ubuntu 24.04 Planned