PT-2026-94846 · Linux · Linux Kernel

CVE-2026-93048

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The mtd add partition() function fails to reject the special offset value MTDPART OFS RETAIN (-3). When this value is passed via the BLKPG ioctl on NAND devices, it causes undefined behavior because the RETAIN value expects the current offset to be the end of the previous partition, whereas in the dynamic partition path, the current offset equals the offset argument itself. This leads to an underflow in the size calculation within the allocate partition() function. Depending on the result of this underflow, the system may either skip erasesize initialization, resulting in erasesize=0 and triggering a WARN ON in the add mtd device() function, or calculate a bogus partition size that results in the creation of a disabled empty partition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102063
CVE-2026-93048
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel