Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: rawnand: validate ONFI extended parameter page sections

nand_flash_detect_ext_param_page() allocates the length declared by the
ONFI parameter page, then treats the data as a fixed header followed by
variable-length sections. It reads that header and advances over sections
without first proving that the fixed page and each current section fit in
the allocation.

Reject pages shorter than the fixed header, track the remaining variable
area while walking sections, and require the ECC section to contain every
field read from struct onfi_ext_ecc_info. Use device-scoped diagnostics
that identify the malformed ONFI section.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

In the Linux kernel MTD RAW NAND driver, the function used to parse ONFI extended parameter pages does not verify that each declared section fits within the allocated buffer. This omission allows a provider‑supplied NAND device to supply a malformed ONFI page that causes the driver to read beyond the buffer bounds, potentially exposing kernel memory or leading to a driver crash. The flaw is an unwarranted buffer over‑read stemming from insufficient input validation.

Affected Systems

The vulnerability concerns the raw NAND driver in the Linux kernel. Any installation using the kernel's MTD rawnand module – which parses ONFI extended parameter pages – is potentially impacted. The flaw applies to all kernel releases that include this code path, and no specific version ranges are supplied. Systems running the raw NAND driver without a patched kernel may be vulnerable.

Risk and Exploitability

The vulnerability is considered low probability of exploitation, with an EPSS score of <1% and no listing in the CISA KEV catalog, indicating limited public interest. A local attacker controlling the NAND device or its firmware can supply a crafted ONFI page; a remote attack path is not described. The lack of an immediate remote exploitation surface reduces overall risk, though kernel memory disclosure remains a concern for affected hosts.

Generated by OpenCVE AI on September 18, 2026 at 08:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the patch validating ONFI extended parameter page sections.
  • If a kernel upgrade cannot be performed immediately, disable the rawnand driver or configure the system to block ONFI parsing for devices that do not require it.
  • Verify that all NAND flash chips in use comply with the ONFI specification and checksum the device firmware before use.

Generated by OpenCVE AI on September 18, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-188
CWE-20

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: validate ONFI extended parameter page sections nand_flash_detect_ext_param_page() allocates the length declared by the ONFI parameter page, then treats the data as a fixed header followed by variable-length sections. It reads that header and advances over sections without first proving that the fixed page and each current section fit in the allocation. Reject pages shorter than the fixed header, track the remaining variable area while walking sections, and require the ECC section to contain every field read from struct onfi_ext_ecc_info. Use device-scoped diagnostics that identify the malformed ONFI section.
Title mtd: rawnand: validate ONFI extended parameter page sections
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:36.910Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89952

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.397

Modified: 2026-09-16T11:17:05.397

Link: CVE-2026-89952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-188

    Reliance on Data/Memory Layout

  • CWE-20

    Improper Input Validation