Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: mchp23k256: use SPI match data for chip caps

The driver stores chip capacity information in both the OF match table
and the SPI id table. Probe currently uses of_device_get_match_data(),
so a non-OF SPI modalias match falls back to mchp23k256_caps even when
the SPI id table selected a different part.

Use spi_get_device_match_data() so SPI id-table driver_data is consumed
when OF match data is absent. This keeps the existing default fallback
while avoiding the wrong MTD geometry for id-table-only matches.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel’s mtd:mchp23k256 driver determines flash chip capacity from either the OF match table or the SPI id table. When the device is detected via a non‑OF SPI modalias, the driver mistakenly falls back to a hard‑coded capacity value, even when the SPI id table specifies a different part. This causes the kernel to configure an incorrect flash geometry, which can result in read/write operations accessing memory outside the intended flash area, leading to data corruption or system instability.

Affected Systems

The flaw exists in all Linux kernel builds that include the mchp23k256 MTD driver before the fix that replaces of_device_get_match_data() with spi_get_device_match_data(). Any device running a kernel version with this driver enabled is at risk; devices using this driver in embedded boards or IoT devices are the primary class of affected systems.

Risk and Exploitability

The vulnerability’s CVSS score of 7.8 indicates a high impact on data integrity and availability. The EPSS score is less than 1%, and it is not listed in KEV, suggesting a low to moderate risk of public exploitation at present. The likely attack vector is local or physical access to the SPI bus, with an attacker able to manipulate the modalias or id table to force an incorrect geometry. While the flaw does not provide an arbitrary code execution path, incorrect geometry can overwrite adjacent memory or corrupt firmware, potentially crashing the system.

Generated by OpenCVE AI on August 18, 2026 at 04:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that applies the patch replacing of_device_get_match_data() with spi_get_device_match_data() for the mchp23k256 driver
  • If a kernel upgrade is not immediately possible, disable the mchp23k256 MTD driver or reconfigure the device so the SPI bus is not exposed to untrusted parties
  • Enable kernel debugging or logging for MTD operations to detect geometry mismatches or memory corruption early

Generated by OpenCVE AI on August 18, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-348
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Mon, 17 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: mchp23k256: use SPI match data for chip caps The driver stores chip capacity information in both the OF match table and the SPI id table. Probe currently uses of_device_get_match_data(), so a non-OF SPI modalias match falls back to mchp23k256_caps even when the SPI id table selected a different part. Use spi_get_device_match_data() so SPI id-table driver_data is consumed when OF match data is absent. This keeps the existing default fallback while avoiding the wrong MTD geometry for id-table-only matches.
Title mtd: mchp23k256: use SPI match data for chip caps
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:11.779Z

Reserved: 2026-07-30T09:28:09.396Z

Link: CVE-2026-68467

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:19:46.527

Modified: 2026-08-17T06:17:56.033

Link: CVE-2026-68467

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-68467 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T04:15:04Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source