CVE-2026-93046

high

Description

In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args() with index -1 The bounds check for the index passed to software_node_get_reference_args() was failing when passed UINT_MAX, this in turn would lead to an out of bound access in the property array. Fix the bound check to also cover the UINT_MAX case.

References

https://git.kernel.org/stable/c/df5466412b362db7adfa78e3e092fe07ac6769a4

https://git.kernel.org/stable/c/ba3dedcf3bd47017307595a7e54924198f018246

https://git.kernel.org/stable/c/b2fa4e8c7e4a33e02e6aaa8f6df72f84cf4aed75

https://git.kernel.org/stable/c/849076df15129e47dd8db751fa18489419ffea56

https://git.kernel.org/stable/c/6cde06887487b4febd14658c9a246616abcc0097

https://git.kernel.org/stable/c/4ebf96d5f834aba7f6d0397db4c421f6078171b9

https://git.kernel.org/stable/c/231bbc04c58f115a505bf3b668ec69ef40a1773b

https://git.kernel.org/stable/c/0631384eadebc66d92d2dd72d57a0263c3877bee

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 6

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00211