GHSA-c7p2-9jv2-f7w3unknown

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Validate...

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

cxl/region: Validate partition index before array access

construct_region() reads cxled->part and uses it to index cxlds->part[] without checking for a negative value. If the partition was never resolved, part remains at its initial value of -1, causing an out-of-bounds array access.

Add a guard to return -EBUSY when part is negative.

The check was dropped during a merge.

🔗 References (4)