Impact
The Linux kernel’s mtd_add_partition() function failed to reject the special offset value MTDPART_OFS_RETAIN (-3). When this value is supplied through the BLKPG ioctl on NAND devices, the kernel calculates an underflowed partition size that leads to an erase size of zero. This condition triggers a WARN_ON in add_mtd_device() and can result in a disabled or incorrectly sized partition, potentially compromising data integrity and kernel stability. The issue does not directly allow code execution, but it can cause kernel misbehavior that might be exploitable by a privileged attacker to destabilize the system.
Affected Systems
This vulnerability applies to any Linux kernel implementation that includes the mtd_add_partition() routine without rejecting MTDPART_OFS_RETAIN. The specific versions affected are those before the introduction of the fix that adds the proper rejection logic; no precise version range is listed in the advisory, so all current kernels prior to the patch containing commit 1a31368bf92e are potentially impacted.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. A local administrator or an attacker with root privileges and the ability to invoke the BLKPG ioctl on a NAND device could trigger the WARN_ON condition. The lack of a remote code execution pathway and the need for privileged access lower the overall risk, but the kernel instability warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA