CVE-2026-45896 PUBLISHED

mtd: intel-dg: Fix accessing regions before setting nregions

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

mtd: intel-dg: Fix accessing regions before setting nregions

The regions array is counted by nregions, but it's set only after accessing it:

[] UBSAN: array-index-out-of-bounds in drivers/mtd/devices/mtd_intel_dg.c:750:15 [] index 0 is out of range for type '<unknown> [*]'

Fix it by also fixing an undesired behavior: the loop silently ignores ENOMEM and continues setting the other entries.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from ceb5ab3cb64637952657be23d347e1c79dd02212 to 721bd22bcf45a63ebd9bd0f478ef721b45cc5383 (excl.)
  • affected from ceb5ab3cb64637952657be23d347e1c79dd02212 to d58fca8513414b15387460b14a7a0a30405b9c9e (excl.)
  • affected from ceb5ab3cb64637952657be23d347e1c79dd02212 to 779c59274d03cc5c07237a2c845dfb71cff77705 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.17 is affected
  • unaffected from 0 to 6.17 (excl.)
  • unaffected from 6.18.14 to 6.18.* (incl.)
  • unaffected from 6.19.4 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References