Executive brief
The Linux kernel's NAND flash memory driver contains a bounds-checking vulnerability in the nand_select_target() function. An attacker with local access could pass an out-of-bounds chip select value, potentially causing memory corruption, system crash, or arbitrary code execution on systems using NAND storage devices.
Technical details
The vulnerability is an off-by-one error in the bounds validation of the 'cs' (chip select) parameter in drivers/mtd/nand/raw/nand_base.c. The condition was checking "if (cs > nanddev_ntargets())" when it should check "if (cs >= nanddev_ntargets())" to properly validate that cs is in the range [0, nanddev_ntargets()). This allows an attacker to pass cs equal to nanddev_ntargets(), bypassing the validation and causing an out-of-bounds array access. Local privilege or physical access may be required depending on the system configuration. The fix changes the comparison operator from '>' to '>='.
Affected products
- Linux Linux kernel Multiple versions (patched in stable series linux-4.x through linux-7.x)
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched