Executive brief
The Linux kernel's MTD (Memory Technology Device) partitioning subsystem failed to properly validate special offset values when adding partitions dynamically via the BLKPG ioctl interface. This could allow a user with appropriate permissions to trigger invalid partition configurations or cause the kernel to generate warnings, potentially affecting system stability or enabling denial-of-service conditions on systems using NAND flash storage.
Technical details
The vulnerability is a validation bypass in mtd_add_partition() where the special offset constant MTDPART_OFS_RETAIN (-3) was not rejected, unlike the similar MTDPART_OFS_APPEND (-1) and MTDPART_OFS_NXTBLK (-2) values. When MTDPART_OFS_RETAIN is passed via BLKPG ioctl, the partition size calculation in allocate_partition() underflows due to improper cur_offset handling, resulting in either erasesize=0 (triggering a kernel WARN_ON) or creation of a disabled empty partition. The fix rejects MTDPART_OFS_RETAIN in mtd_add_partition() to prevent the invalid code path, consistent with existing handling of other special offsets.
Affected products
- Linux Linux kernel 5.13 and later (introduced by commits 5daa7b21496a and 1a31368bf92e, fixed in 2026-09-17)
Timeline
- 2026-09-17: patched: Fix committed to Linux kernel