In the Linux kernel, the following vulnerability has been resolved:
mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
Sashiko noticed an out-of-bounds read [1].
In spi_nor_params_show(), the snor_f_names array is passed to
spi_nor_print_flags() using sizeof(snor_f_names).
Since snor_f_names is an array of pointers, sizeof() returns the total
number of bytes occupied by the pointers
(element_count * sizeof(void *))
rather than the element count itself. On 64-bit systems, this makes the
passed length 8x larger than intended.
Inside spi_nor_print_flags(), the 'names_len' argument is used to
bounds-check the 'names' array access. An out-of-bounds read occurs
if a flag bit is set that exceeds the array's actual element count
but is within the inflated byte-size count.
Correct this by using ARRAY_SIZE() to pass the actual number of
string pointers in the array.
References
Configurations
Configuration 1 (hide)
|
History
19 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Jun 2026, 03:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/34bdcfb496b29f9a52431194f94473b37fb8c162 - Patch | |
| References | () https://git.kernel.org/stable/c/9a80c458320e0514e11945402dd6e48fcee05524 - Patch | |
| References | () https://git.kernel.org/stable/c/c0b654bc0b76a1da102d9138be1ed1223bd99310 - Patch | |
| References | () https://git.kernel.org/stable/c/ca18c180b053f6ce80394322b314ac721c316af7 - Patch | |
| References | () https://git.kernel.org/stable/c/e47029b977e747cb3a9174308fd55762cce70147 - Patch | |
| First Time |
Linux linux Kernel
Linux |
|
| CWE | CWE-125 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
30 May 2026, 11:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
28 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 10:16
Updated : 2026-06-19 13:16
NVD link : CVE-2026-46190
Mitre link : CVE-2026-46190
CVE.ORG link : CVE-2026-46190
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-125
Out-of-bounds Read
