{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89954","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.777Z","datePublished":"2026-09-16T10:32:38.355Z","dateUpdated":"2026-09-16T14:40:35.830Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:35.830Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: afs: validate v2 image info bounds\n\nThe AFS v2 parser uses footer[8] to locate the image information block\ninside the current erase block, then uses the image information\nregion_count to walk entries from a fixed local array. The footer offset\nand region count come from flash contents and are not checked against the\nerase block or the local image-info array before use.\n\nReject v2 entries whose image information offset would underflow the\nerase block calculation, and reject region counts that cannot fit in the\nlocal image-info array before walking region entries."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The AFS v2 parser runs from parse_mtd_partitions() during local MTD/physmap probe, reading on-flash ARM Firmware Suite footers via mtd_read(); no network protocol, Bluetooth/Wi-Fi path, or USB gadget/host handler invokes this code.\nAC:L - An attacker who controls the flash image can plant valid AFS v2 magic and CRC and set footer[8] and region_count arbitrarily, so the unsigned info-block offset and the region walk run deterministically with no race or layout condition outside attacker control.\nPR:N - parse_afs_partitions() runs automatically at boot/probe on affected ARM/physmap systems with no credential or capability check; crafted AFS metadata can be delivered in firmware/OTA/supply-chain flash contents without a local OS account.\nUI:N - Partition parsing runs as part of MTD driver initialization at boot or bind; no separate victim action such as mounting a filesystem or opening a device node is required.\nS:U - The stack over-read and any resulting oops remain inside the host kernel; this is not a VM escape, IOMMU bypass, or sandbox breakout.\nC:H - Attacker-controlled region_count drives an unbounded read past the on-stack imginfo[36] array, and kstrdup() of a possibly non-NUL-terminated footer name can copy that kernel stack/adjacent memory into a partition name far beyond a small bounded leak.\nI:L - OOB-derived region offset/size and repeated kstrdup() results are stored in the registered mtd_partition object, modifying kernel flash-layout metadata, but the loop does not perform an out-of-bounds write or yield a control-flow hijack primitive.\nA:H - Walking region_count past imginfo[] reaches unmapped stack or vmalloc pages and oopses or panics the kernel; a huge count can also livelock probe and exhaust memory via kstrdup in the loop."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mtd/parsers/afs.c"],"versions":[{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"1bec05a68414cf8d0cab6cb42445b8603f32ffc4","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"3ad8ff12fd44b08af9212ac4883a7e29d2ab7348","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"875daa3c750814ff2e2dc050239c390048f0bcd0","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"da740539e8f370767317e24615349b9342a6e773","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"1edea8900ca3e405c1421d8b5c29f97107874f72","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"18916f475057cbd2fb8ea6ae86e6b85884ad1d53","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"d14e6298139f58a87a87d7022e26a7f37f0ddce7","status":"affected","versionType":"git"},{"version":"b7cf5e2830bbb128699d7635ce8404b7f605bc95","lessThan":"e9290031f736e99ad17c25c00311c92c266843b7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mtd/parsers/afs.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1bec05a68414cf8d0cab6cb42445b8603f32ffc4"},{"url":"https://git.kernel.org/stable/c/3ad8ff12fd44b08af9212ac4883a7e29d2ab7348"},{"url":"https://git.kernel.org/stable/c/875daa3c750814ff2e2dc050239c390048f0bcd0"},{"url":"https://git.kernel.org/stable/c/da740539e8f370767317e24615349b9342a6e773"},{"url":"https://git.kernel.org/stable/c/1edea8900ca3e405c1421d8b5c29f97107874f72"},{"url":"https://git.kernel.org/stable/c/18916f475057cbd2fb8ea6ae86e6b85884ad1d53"},{"url":"https://git.kernel.org/stable/c/d14e6298139f58a87a87d7022e26a7f37f0ddce7"},{"url":"https://git.kernel.org/stable/c/e9290031f736e99ad17c25c00311c92c266843b7"}],"title":"mtd: afs: validate v2 image info bounds","x_generator":{"engine":"bippy-1.2.0"}}}}