{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97423","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.868Z","datePublished":"2026-09-24T16:03:35.458Z","dateUpdated":"2026-09-25T12:43:59.015Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-25T12:43:59.015Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Validate partition index before array access\n\nconstruct_region() reads cxled->part and uses it to index\ncxlds->part[] without checking for a negative value. If the\npartition was never resolved, part remains at its initial value\nof -1, causing an out-of-bounds array access.\n\nAdd a guard to return -EBUSY when part is negative.\n\nThe check was dropped during a merge."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/region.c"],"versions":[{"version":"b6faa9c613787b894913638a76030018f6d62d54","lessThan":"06322da06116f1ee52271dd4d84dc69580087df7","status":"affected","versionType":"git"},{"version":"b6faa9c613787b894913638a76030018f6d62d54","lessThan":"16329b510f76e5b824e05bf8add8b29850f1f16f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/cxl/core/region.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/06322da06116f1ee52271dd4d84dc69580087df7"},{"url":"https://git.kernel.org/stable/c/16329b510f76e5b824e05bf8add8b29850f1f16f"}],"title":"cxl/region: Validate partition index before array access","x_generator":{"engine":"bippy-1.2.0"}}}}