Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array is counted by nregions, but it's set only after accessing it: [] UBSAN: array-index-out-of-bounds in drivers/mtd/devices/mtd_intel_dg.c:750:15 [] index 0 is out of range for type '<unknown> [*]' Fix it by also fixing an undesired behavior: the loop silently ignores ENOMEM and continues setting the other entries.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.17, < 6.18.14 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/721bd22bcf45a63ebd9bd0f478ef721b45cc5383Patch
- https://git.kernel.org/stable/c/779c59274d03cc5c07237a2c845dfb71cff77705Patch
- https://git.kernel.org/stable/c/d58fca8513414b15387460b14a7a0a30405b9c9ePatch
FAQ
What is CVE-2026-45896?
CVE-2026-45896 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array is counted by nregions, but it's set only after acc...
How severe is CVE-2026-45896?
CVE-2026-45896 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45896?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.