Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: core: Validate connected lane counts

The connected lane count is used by TX equalization code to index arrays
sized by UFS_MAX_LANES. Reject zero and out-of-range RX or TX lane counts
before they can be propagated.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service via out-of-bounds array indexing
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel SCSI UFS subsystem had a flaw where the connected lane count, used as an index into arrays sized by UFS_MAX_LANES, was not validated against zero or values exceeding the supported range. This oversight allowed an attacker that could influence the lane count value to cause the kernel to access memory outside the intended bounds, potentially leading to a crash, memory corruption, or unintended information disclosure. The issue is reflected by CWE-125 and CWE-787 weaknesses in array index handling.

Affected Systems

All Linux kernel deployments that contain the unpatched UFS core code are affected. The vulnerability does not specify an exact kernel version, so any system running an earlier kernel build before the applied patch is part of the risk scope.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability that this vulnerability will be actively exploited, and it is not listed in the CISA KEV catalog. The attack vector requires local access to a UFS device, typically necessitating privileged interaction with the SCSI subsystem or a compromised driver. While the overarching risk is mitigated by the low exploit likelihood, the potential for system instability or denial of service warrants prompt attention.

Generated by OpenCVE AI on September 19, 2026 at 05:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the fixed lane count validation logic.
  • Restrict access to UFS devices by ensuring strict permission controls and limiting unprivileged users from interacting with SCSI device nodes.
  • If an immediate kernel upgrade is not feasible, monitor the system for signs of instability and consider disabling or limiting UFS support until the patch can be applied.

Generated by OpenCVE AI on September 19, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX equalization code to index arrays sized by UFS_MAX_LANES. Reject zero and out-of-range RX or TX lane counts before they can be propagated.
Title scsi: ufs: core: Validate connected lane counts
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:56.397Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:49.843

Modified: 2026-09-17T17:17:49.843

Link: CVE-2026-92478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:15:17Z

Weaknesses