Description
In the Linux kernel, the following vulnerability has been resolved:

ubi: Fix rollback for explicit UBI device numbers

ubi_init_attach() rolls back module initialization failures by scanning
ubi_devices[0..i-1], where i is the mtd= parameter index. That assumes
the parameter index matches the UBI device number.

That assumption is not true when mtd= specifies an explicit ubi_num. A
successfully attached device can be stored at a higher ubi_devices[]
slot, and a later failure can miss it during rollback.

Scan the full ubi_devices[] array and detach by the actual array index,
matching the way UBI devices are stored.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Device Mismanagement
Action: Update Kernel
AI Analysis

Impact

The Linux kernel bug limits the ubi_init_attach() rollback process to the mtd index used during initialization. When an explicit UBI device number is supplied via the mtd= parameter, the device may be stored in a higher index in the ubi_devices[] array. A later attachment failure thus skips the entry during rollback, leaving a stale reference, which can confuse device enumeration and lead to incorrect device states. The flaw does not enable arbitrary code execution but can cause instability in UBI handling.

Affected Systems

The flaw is present in the UBI subsystem of the Linux kernel, part of all mainstream Linux distributions that enable UBI support. No specific vendor or kernel version is listed, so all kernels that include this subsystem before the commit are exposed.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of widespread exploitation. With no publicly available exploit, the risk is confined to environments that load modules with explicit ubi_num configurations, typically requiring local or root access to trigger an attachment failure. Overall, the threat is low, though the kernel may exhibit device mismanagement if the bug is activated.

Generated by OpenCVE AI on September 20, 2026 at 01:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version where the rollback logic has been corrected.
  • If an upgrade is not immediately possible, avoid using explicit ubi_num values in the mtd= parameter until a patched kernel is installed.
  • Disable UBI support in the kernel configuration (CONFIG_UBI) if UBI is not required for your system.

Generated by OpenCVE AI on September 20, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ubi: Fix rollback for explicit UBI device numbers ubi_init_attach() rolls back module initialization failures by scanning ubi_devices[0..i-1], where i is the mtd= parameter index. That assumes the parameter index matches the UBI device number. That assumption is not true when mtd= specifies an explicit ubi_num. A successfully attached device can be stored at a higher ubi_devices[] slot, and a later failure can miss it during rollback. Scan the full ubi_devices[] array and detach by the actual array index, matching the way UBI devices are stored.
Title ubi: Fix rollback for explicit UBI device numbers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:28.730Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.900

Modified: 2026-09-17T17:17:16.900

Link: CVE-2026-90216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime