Junglewise Threat Intelligence

CVE-2026-93048: Linux kernel MTD partition offset validation flaw

CVE-2026-93048 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MTD (Memory Technology Device) partitioning subsystem failed to properly validate special offset values when adding partitions dynamically via the BLKPG ioctl interface. This could allow a user with appropriate permissions to trigger invalid partition configurations or cause the kernel to generate warnings, potentially affecting system stability or enabling denial-of-service conditions on systems using NAND flash storage.

Technical details

The vulnerability is a validation bypass in mtd_add_partition() where the special offset constant MTDPART_OFS_RETAIN (-3) was not rejected, unlike the similar MTDPART_OFS_APPEND (-1) and MTDPART_OFS_NXTBLK (-2) values. When MTDPART_OFS_RETAIN is passed via BLKPG ioctl, the partition size calculation in allocate_partition() underflows due to improper cur_offset handling, resulting in either erasesize=0 (triggering a kernel WARN_ON) or creation of a disabled empty partition. The fix rejects MTDPART_OFS_RETAIN in mtd_add_partition() to prevent the invalid code path, consistent with existing handling of other special offsets.

Affected products

  • Linux Linux kernel 5.13 and later (introduced by commits 5daa7b21496a and 1a31368bf92e, fixed in 2026-09-17)

Timeline

  • 2026-09-17: patched: Fix committed to Linux kernel

Related threats