Description
In the Linux kernel, the following vulnerability has been resolved:

software node: Fix software_node_get_reference_args() with index -1

The bounds check for the index passed to
software_node_get_reference_args() was failing when passed UINT_MAX,
this in turn would lead to an out of bound access in the property
array. Fix the bound check to also cover the UINT_MAX case.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Linux kernel has a flaw in software_node_get_reference_args() where the bounds check fails for an index value of UINT_MAX, causing an out-of-bounds read of the property array. This defect could expose kernel memory contents to a malicious actor, leading to confidentiality compromise. The CVSS score of 7 indicates a moderate severity vulnerability classified as a buffer over-read (CWE-119).

Affected Systems

All Linux kernel releases prior to the inclusion of the fix commit are affected. The issue is present in every vendor-supplied kernel that has not yet applied the patch, regardless of distribution or version.

Risk and Exploitability

The EPSS score of less than 1% suggests that exploitation is very unlikely under typical circumstances, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is from code that invokes software_node_get_reference_args() with an index of UINT_MAX, whether that code is part of the kernel itself or an in-kernel extension. While no direct privilege escalation path is documented, the resulting memory disclosure could eventually aid further attacks, and the out-of-bounds read could precipitate a crash or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 16:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a release that contains the patch commit for the software_node_get_reference_args bounds check bug.
  • If a kernel update is not immediately feasible, restrict privileged components from invoking software_node_get_reference_args(), or disable the software node feature through kernel configuration or runtime options.
  • Enable kernel hardening mechanisms such as SELinux, AppArmor, or grsecurity patches to limit the impact of potential memory disclosure from kernel code execution paths.

Generated by OpenCVE AI on September 19, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args() with index -1 The bounds check for the index passed to software_node_get_reference_args() was failing when passed UINT_MAX, this in turn would lead to an out of bound access in the property array. Fix the bound check to also cover the UINT_MAX case.
Title software node: Fix software_node_get_reference_args() with index -1
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:47.049Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:57.843

Modified: 2026-09-18T18:18:19.230

Link: CVE-2026-93046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:12Z

Weaknesses

No weakness.