{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-46190",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-05-13T15:03:33.104Z",
        "datePublished": "2026-05-28T09:36:44.017Z",
        "dateUpdated": "2026-08-05T12:30:19.706Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:30:19.706Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()\n\nSashiko noticed an out-of-bounds read [1].\n\nIn spi_nor_params_show(), the snor_f_names array is passed to\nspi_nor_print_flags() using sizeof(snor_f_names).\n\nSince snor_f_names is an array of pointers, sizeof() returns the total\nnumber of bytes occupied by the pointers\n\t(element_count * sizeof(void *))\nrather than the element count itself. On 64-bit systems, this makes the\npassed length 8x larger than intended.\n\nInside spi_nor_print_flags(), the 'names_len' argument is used to\nbounds-check the 'names' array access. An out-of-bounds read occurs\nif a flag bit is set that exceeds the array's actual element count\nbut is within the inflated byte-size count.\n\nCorrect this by using ARRAY_SIZE() to pass the actual number of\nstring pointers in the array."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code is a debugfs `params` file (mode 0444) under CONFIG_DEBUG_FS, reachable only by a local VFS read of /sys/kernel/debug/spi-nor/<dev>/params; there is no network or physical path.\nAC:L - While the read itself is reliable, the OOB only manifests if a flag bit ≥17 is set in nor->flags; per the directive to consider the most severe reasonable case and resolve uncertainty toward higher severity, the read is treated as reliably performable.\nPR:L - The file is created world-readable (0444), and on reasonable embedded/dev SPI-NOR deployments where debugfs is mounted and traversable by non-root, an unprivileged local user can read it.\nUI:N - Exploitation only requires the attacker to read the debugfs file; no victim action is needed.\nS:U - The defect is confined to the kernel's own memory and security authority with no crossing of a trust boundary such as VM or IOMMU.\nC:H - An out-of-bounds read that, when triggered, makes seq_puts() dereference an adjacent-memory-derived pointer and emit a kernel string into readable output — not strictly bounded to a few bytes.\nI:N - The operation is purely a read path emitting to a seq_file; it provides no memory-write or control-flow primitive.\nA:H - If the out-of-array slot holds a non-NULL invalid pointer, seq_puts() dereferences a wild pointer, which can oops/crash the kernel."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/mtd/spi-nor/debugfs.c"
                    ],
                    "versions": [
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "231b8e1f604f6e0a7e100536f506cdf482e2c5f5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "9a80c458320e0514e11945402dd6e48fcee05524",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "ca18c180b053f6ce80394322b314ac721c316af7",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "34bdcfb496b29f9a52431194f94473b37fb8c162",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "c0b654bc0b76a1da102d9138be1ed1223bd99310",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0257be79fc4a16a3252ce80aa13b3640f728c425",
                            "lessThan": "e47029b977e747cb3a9174308fd55762cce70147",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/mtd/spi-nor/debugfs.c"
                    ],
                    "versions": [
                        {
                            "version": "5.19",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.19",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.176",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.140",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.88",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.30",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0.7",
                            "lessThanOrEqual": "7.0.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.1.176"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.6.140"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.12.88"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.18.30"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "7.0.7"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "7.1"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/231b8e1f604f6e0a7e100536f506cdf482e2c5f5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9a80c458320e0514e11945402dd6e48fcee05524"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ca18c180b053f6ce80394322b314ac721c316af7"
                },
                {
                    "url": "https://git.kernel.org/stable/c/34bdcfb496b29f9a52431194f94473b37fb8c162"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c0b654bc0b76a1da102d9138be1ed1223bd99310"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e47029b977e747cb3a9174308fd55762cce70147"
                }
            ],
            "title": "mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}