Description
In the Linux kernel, the following vulnerability has been resolved:

mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()

mtd_add_partition() does not reject the special offset value
MTDPART_OFS_RETAIN (-3), which leads to a WARN_ON in
add_mtd_device() when called through the BLKPG ioctl on NAND
devices. The RETAIN value depends on cur_offset being the end of
the previous partition, but in the dynamic partition path
cur_offset equals the offset argument itself, causing undefined
behavior.

Commit 5daa7b21496a ("mtd: prepare partition add and del functions
for ioctl requests") introduced mtd_add_partition() and correctly
rejected MTDPART_OFS_APPEND (-1) and MTDPART_OFS_NXTBLK (-2),
since those special offsets rely on cur_offset tracking the
previous partition's end. However, commit 1a31368bf92e ("mtd: add a flags
for partitions which should just leave smth. after them")
later added MTDPART_OFS_RETAIN (-3) for the static
partition table path without updating mtd_add_partition() to
also reject this value.

With offset=-3 passed via BLKPG, the RETAIN size calculation in
allocate_partition() underflows (parent_size - 0xFFFFFFFFFFFFFFFD
= parent_size + 3). If the underflow result does not appear to
leave enough space, allocate_partition() jumps to out_register via
goto, skipping erasesize initialization. This results in
erasesize=0, which triggers:

WARN_ON((!mtd->erasesize || !master->_erase) &&
!(mtd->flags & MTD_NO_ERASE))

in add_mtd_device(). If the underflow result appears to leave
enough space, a bogus partition size is calculated, but the
"out of reach" sanity check catches the invalid offset and
creates a disabled empty partition (offset=0, size=0) instead
of returning an error.

Fix this by adding MTDPART_OFS_RETAIN to the rejection list in
mtd_add_partition(), consistent with the existing handling of
APPEND and NXTBLK.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel instability and denial of service via misconfigured MTD partitions
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s mtd_add_partition() function failed to reject the special offset value MTDPART_OFS_RETAIN (-3). When this value is supplied through the BLKPG ioctl on NAND devices, the kernel calculates an underflowed partition size that leads to an erase size of zero. This condition triggers a WARN_ON in add_mtd_device() and can result in a disabled or incorrectly sized partition, potentially compromising data integrity and kernel stability. The issue does not directly allow code execution, but it can cause kernel misbehavior that might be exploitable by a privileged attacker to destabilize the system.

Affected Systems

This vulnerability applies to any Linux kernel implementation that includes the mtd_add_partition() routine without rejecting MTDPART_OFS_RETAIN. The specific versions affected are those before the introduction of the fix that adds the proper rejection logic; no precise version range is listed in the advisory, so all current kernels prior to the patch containing commit 1a31368bf92e are potentially impacted.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. A local administrator or an attacker with root privileges and the ability to invoke the BLKPG ioctl on a NAND device could trigger the WARN_ON condition. The lack of a remote code execution pathway and the need for privileged access lower the overall risk, but the kernel instability warrants prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 09:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit adding MTDPART_OFS_RETAIN to the rejection list (e.g., any kernel build after commit 1a31368bf92e).
  • If an update is not immediately available, avoid using BLKPG to create partitions with the MTDPART_OFS_RETAIN offset on NAND devices; configure such partitions statically via the device tree or kernel boot parameters instead.
  • After any MTD partition changes, monitor kernel logs for WARN_ON messages and, if the warning appears, consider rebooting the system to ensure kernel stability.

Generated by OpenCVE AI on September 19, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() mtd_add_partition() does not reject the special offset value MTDPART_OFS_RETAIN (-3), which leads to a WARN_ON in add_mtd_device() when called through the BLKPG ioctl on NAND devices. The RETAIN value depends on cur_offset being the end of the previous partition, but in the dynamic partition path cur_offset equals the offset argument itself, causing undefined behavior. Commit 5daa7b21496a ("mtd: prepare partition add and del functions for ioctl requests") introduced mtd_add_partition() and correctly rejected MTDPART_OFS_APPEND (-1) and MTDPART_OFS_NXTBLK (-2), since those special offsets rely on cur_offset tracking the previous partition's end. However, commit 1a31368bf92e ("mtd: add a flags for partitions which should just leave smth. after them") later added MTDPART_OFS_RETAIN (-3) for the static partition table path without updating mtd_add_partition() to also reject this value. With offset=-3 passed via BLKPG, the RETAIN size calculation in allocate_partition() underflows (parent_size - 0xFFFFFFFFFFFFFFFD = parent_size + 3). If the underflow result does not appear to leave enough space, allocate_partition() jumps to out_register via goto, skipping erasesize initialization. This results in erasesize=0, which triggers: WARN_ON((!mtd->erasesize || !master->_erase) && !(mtd->flags & MTD_NO_ERASE)) in add_mtd_device(). If the underflow result appears to leave enough space, a bogus partition size is calculated, but the "out of reach" sanity check catches the invalid offset and creates a disabled empty partition (offset=0, size=0) instead of returning an error. Fix this by adding MTDPART_OFS_RETAIN to the rejection list in mtd_add_partition(), consistent with the existing handling of APPEND and NXTBLK.
Title mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:39.008Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.080

Modified: 2026-09-17T17:17:58.080

Link: CVE-2026-93048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses

No weakness.