Bug 2516268 (CVE-2026-72155)
| Summary: | CVE-2026-72155 kernel: mtd: spi-nor: swp: Improve locking user experience | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's `mtd: spi-nor: swp` component. When a user attempts to unlock specific blocks on a Serial Peripheral Interface (SPI) NOR flash device, particularly those at the beginning of the device, the operation may fail. This occurs due to an incorrect calculation of the `lock_len` parameter, which prevents the intended blocks from being unlocked. The consequence is that the user's request to unlock certain flash memory regions is not properly executed, potentially leading to unexpected device behavior or operational limitations.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 06:03:35 UTC
|