PT-2026-72179 · Linux · Linux Kernel
CVE-2026-68467
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
mtd: mchp23k256 driver where chip capacity information is stored in both the Open Firmware (OF) match table and the SPI id table. The probe process uses the of device get match data() function, causing non-OF SPI modalias matches to incorrectly fall back to mchp23k256 caps even when the SPI id table has selected a different part. This results in the application of incorrect Memory Technology Device (MTD) geometry for matches relying solely on the id-table.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel