{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93046","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-17T15:57:05.658Z","datePublished":"2026-09-17T16:10:37.691Z","dateUpdated":"2026-09-18T17:55:47.049Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:47.049Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoftware node: Fix software_node_get_reference_args() with index -1\n\nThe bounds check for the index passed to\nsoftware_node_get_reference_args() was failing when passed UINT_MAX,\nthis in turn would lead to an out of bound access in the property\narray. Fix the bound check to also cover the UINT_MAX case."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The OOB is in software_node_get_reference_args() in drivers/base/swnode.c, reached only from in-kernel fwnode_property_get_reference_args()/fwnode_find_reference() on local probe/consumer paths (led_get → fwnode_led_get, swnode_gpio_get_reference, IIO/reset/mailbox); the wrapping index is a kernel argument, not bytes from a packet or remote peer.\nAC:H - Only index==UINT_MAX makes (index+1)*sizeof(*ref) wrap to 0 so the bound is skipped. led_get() passes -1 into fwnode_led_get(), but that value is overwritten by fwnode_property_match_string() for every in-tree con_id (v4l2_subdev_get_privacy_led \"privacy\", yogabook \"pen-icon-led\"); other negative errnos do not wrap on 64-bit, so the attacker cannot force UINT_MAX against a live DEV_PROP_REF.\nPR:L - The lookup runs in driver probe and consumer helpers (led_get from v4l2_subdev_get_privacy_led, swnode_find_gpio, fwnode_find_reference) with no capability check; an unprivileged local user can provoke those paths by opening a consumer device node or causing bind, without init-namespace root or user-namespace tricks.\nUI:N - software_node_get_reference_args() runs automatically inside fwnode_find_reference()/led_get()/swnode_gpio_get_reference during probe or consumer get; no other user must mount media, open a file, or confirm a prompt.\nS:U - The wild software_node_ref_args load, fwnode_handle_get() and any oops stay inside the host kernel; no VM, IOMMU or sandbox boundary is crossed.\nC:H - ref=&ref_array[UINT_MAX] reads a full software_node_ref_args (swnode, fwnode, nargs, args[NR_FWNODE_REFERENCE_ARGS]) from wrapped/wild memory; those pointers and u64 args[] are not a few bounded bytes and can be returned to GPIO/LED/IIO consumers.\nI:H - The OOB bytes are used as ref->swnode/ref->fwnode; software_node_fwnode() or fwnode_handle_get() then software_node_get() → kobject_get() runs on that pointer, an ops-vtable call and a refcount write at a non-object address — a control-flow-relevant primitive.\nA:H - The wrapped ref_array[UINT_MAX] pointer is immediately dereferenced (ref->swnode / ref->fwnode / fwnode_handle_get()), which oopses or panics the kernel (KASAN slab-OOB or wild-pointer fault)."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/base/swnode.c"],"versions":[{"version":"142acd739eb6f08c148a96ae8309256f1422ff4b","lessThan":"6cde06887487b4febd14658c9a246616abcc0097","status":"affected","versionType":"git"},{"version":"56ce76e8d406cc72b89aee7931df5cf3f18db49d","lessThan":"0631384eadebc66d92d2dd72d57a0263c3877bee","status":"affected","versionType":"git"},{"version":"9324127b07dde8529222dc19233aa57ec810856c","lessThan":"b2fa4e8c7e4a33e02e6aaa8f6df72f84cf4aed75","status":"affected","versionType":"git"},{"version":"f9397cf7bfb680799fb8c7f717c8f756384c3280","lessThan":"4ebf96d5f834aba7f6d0397db4c421f6078171b9","status":"affected","versionType":"git"},{"version":"4b3383110b6df48e0ba5936af2cb68d5eb6bd43b","lessThan":"849076df15129e47dd8db751fa18489419ffea56","status":"affected","versionType":"git"},{"version":"31e4e12e0e9609850cefd4b2e1adf782f56337d6","lessThan":"df5466412b362db7adfa78e3e092fe07ac6769a4","status":"affected","versionType":"git"},{"version":"31e4e12e0e9609850cefd4b2e1adf782f56337d6","lessThan":"231bbc04c58f115a505bf3b668ec69ef40a1773b","status":"affected","versionType":"git"},{"version":"31e4e12e0e9609850cefd4b2e1adf782f56337d6","lessThan":"ba3dedcf3bd47017307595a7e54924198f018246","status":"affected","versionType":"git"},{"version":"7af18e42bdefe1dba5bcb32555a4d524fd504939","status":"affected","versionType":"git"},{"version":"5.10.239","lessThan":"5.10.270","status":"affected","versionType":"semver"},{"version":"5.15.186","lessThan":"5.15.221","status":"affected","versionType":"semver"},{"version":"6.1.142","lessThan":"6.1.188","status":"affected","versionType":"semver"},{"version":"6.6.95","lessThan":"6.6.157","status":"affected","versionType":"semver"},{"version":"6.12.35","lessThan":"6.12.110","status":"affected","versionType":"semver"},{"version":"6.15.4","lessThan":"6.16","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/base/swnode.c"],"versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.239","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.186","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.142","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.95","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.35","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6cde06887487b4febd14658c9a246616abcc0097"},{"url":"https://git.kernel.org/stable/c/0631384eadebc66d92d2dd72d57a0263c3877bee"},{"url":"https://git.kernel.org/stable/c/b2fa4e8c7e4a33e02e6aaa8f6df72f84cf4aed75"},{"url":"https://git.kernel.org/stable/c/4ebf96d5f834aba7f6d0397db4c421f6078171b9"},{"url":"https://git.kernel.org/stable/c/849076df15129e47dd8db751fa18489419ffea56"},{"url":"https://git.kernel.org/stable/c/df5466412b362db7adfa78e3e092fe07ac6769a4"},{"url":"https://git.kernel.org/stable/c/231bbc04c58f115a505bf3b668ec69ef40a1773b"},{"url":"https://git.kernel.org/stable/c/ba3dedcf3bd47017307595a7e54924198f018246"}],"title":"software node: Fix software_node_get_reference_args() with index -1","x_generator":{"engine":"bippy-1.2.0"}}}}