Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: afs: validate v2 image info bounds

The AFS v2 parser uses footer[8] to locate the image information block
inside the current erase block, then uses the image information
region_count to walk entries from a fixed local array. The footer offset
and region count come from flash contents and are not checked against the
erase block or the local image-info array before use.

Reject v2 entries whose image information offset would underflow the
erase block calculation, and reject region counts that cannot fit in the
local image-info array before walking region entries.
Published: 2026-09-16
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a bounds‑checking flaw in the AFS v2 image parser of the Linux kernel. The parser reads footer[8] from flash memory to locate an image information block and uses the region_count value from the image to index a fixed‑size local array. Because neither the footer offset nor the region_count is validated against the size of the erase block or the array length, an attacker can supply crafted flash data that causes the parser to read or write past the bounds of the array. This memory corruption in kernel space can result in arbitrary code execution or a kernel crash, effectively allowing privilege escalation.

Affected Systems

All Linux kernel builds that include the vulnerable AFS v2 parser before the fix are affected. The product is the Linux kernel distributed by the Linux community. No specific kernel version numbers are listed, therefore any kernel that has not yet incorporated the commit series referenced in the advisory could be at risk.

Risk and Exploitability

The CVSS score of 8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, at present, exploitation is unlikely, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an attacker to have local access to flash storage or the capability to write a crafted firmware image, making the threat most relevant to embedded devices or systems with exposed MTD interfaces. If an attacker succeeds in delivering a malicious flash image, the unchecked bounds could overwrite kernel memory, leading to privilege escalation or a denial‑of‑service condition.

Generated by OpenCVE AI on September 18, 2026 at 08:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the AFS v2 parser bounds‑check fix referenced in the advisory commits.
  • Reboot the system after applying the update to ensure that kernel memory is refreshed.
  • Restrict write access to flash storage so that only trusted firmware update processes can modify the contents.
  • Verify that any firmware images stored on flash are signed or otherwise authenticated before being installed.

Generated by OpenCVE AI on September 18, 2026 at 08:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-126

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: afs: validate v2 image info bounds The AFS v2 parser uses footer[8] to locate the image information block inside the current erase block, then uses the image information region_count to walk entries from a fixed local array. The footer offset and region count come from flash contents and are not checked against the erase block or the local image-info array before use. Reject v2 entries whose image information offset would underflow the erase block calculation, and reject region counts that cannot fit in the local image-info array before walking region entries.
Title mtd: afs: validate v2 image info bounds
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:35.830Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.667

Modified: 2026-09-16T15:18:20.140

Link: CVE-2026-89954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses