Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array… (CVE-2026-45896)
In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array is counted by nregions, but it's set only after accessing it: [] UBSAN: array-index-out-of-bounds in drivers/mtd/devices/mtd_intel_dg.c:750:15 [] index 0 is out of range for type '<unknown> [*]' Fix it by also fixing an undesired behavior: the loop silently ignores ENOMEM and continues setting the other entries.
AI Analysis
Technical Summary
The Linux kernel mtd intel-dg driver contained a vulnerability where the regions array was accessed before the nregions variable, which counts the array elements, was initialized. This caused an out-of-bounds array access detected by UBSAN at drivers/mtd/devices/mtd_intel_dg.c line 750. Additionally, the code silently ignored ENOMEM errors during initialization, which was corrected. The vulnerability is classified under CWE-129 (Improper Validation of Array Index) and has a CVSS 3.1 vector indicating local attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, and high impact on confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows local attackers with low privileges to cause out-of-bounds memory access in the kernel, potentially leading to full compromise of confidentiality, integrity, and availability of the affected system. This can result in system crashes, data corruption, or privilege escalation. However, no known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix links are provided, users should monitor vendor communications for updates. Avoid running untrusted code with local access until a fix is applied.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array… (CVE-2026-45896)
Description
In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting nregions The regions array is counted by nregions, but it's set only after accessing it: [] UBSAN: array-index-out-of-bounds in drivers/mtd/devices/mtd_intel_dg.c:750:15 [] index 0 is out of range for type '<unknown> [*]' Fix it by also fixing an undesired behavior: the loop silently ignores ENOMEM and continues setting the other entries.
CVSS v3.1
Score 7.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel mtd intel-dg driver contained a vulnerability where the regions array was accessed before the nregions variable, which counts the array elements, was initialized. This caused an out-of-bounds array access detected by UBSAN at drivers/mtd/devices/mtd_intel_dg.c line 750. Additionally, the code silently ignored ENOMEM errors during initialization, which was corrected. The vulnerability is classified under CWE-129 (Improper Validation of Array Index) and has a CVSS 3.1 vector indicating local attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, and high impact on confidentiality, integrity, and availability.
Potential Impact
The vulnerability allows local attackers with low privileges to cause out-of-bounds memory access in the kernel, potentially leading to full compromise of confidentiality, integrity, and availability of the affected system. This can result in system crashes, data corruption, or privilege escalation. However, no known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix links are provided, users should monitor vendor communications for updates. Avoid running untrusted code with local access until a fix is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x95w-mwf5-x656
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45896"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a3ef7ee27e9c79719034aa9
Added to database: 06/26/2026, 22:06:38 UTC
Last enriched: 06/26/2026, 22:49:03 UTC
Last updated: 07/31/2026, 19:30:24 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.