Impact
The Linux kernel bug limits the ubi_init_attach() rollback process to the mtd index used during initialization. When an explicit UBI device number is supplied via the mtd= parameter, the device may be stored in a higher index in the ubi_devices[] array. A later attachment failure thus skips the entry during rollback, leaving a stale reference, which can confuse device enumeration and lead to incorrect device states. The flaw does not enable arbitrary code execution but can cause instability in UBI handling.
Affected Systems
The flaw is present in the UBI subsystem of the Linux kernel, part of all mainstream Linux distributions that enable UBI support. No specific vendor or kernel version is listed, so all kernels that include this subsystem before the commit are exposed.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of widespread exploitation. With no publicly available exploit, the risk is confined to environments that load modules with explicit ubi_num configurations, typically requiring local or root access to trigger an attachment failure. Overall, the threat is low, though the kernel may exhibit device mismanagement if the bug is activated.
OpenCVE Enrichment
Debian DLA
Debian DSA