What is CVE-2026-68467?
This vulnerability in the Linux kernel's MTD driver involves incorrect handling of chip capacity data during SPI modalias matching. It affects the "mchp23k256" driver because the "of_device_get_match_data()" function only works for Device Tree matches, potentially impacting SPI-connected devices. A kernel update is required to address this issue.
Azərbaycanca: Linux kernel-də MTD sürücüsündə aşkar edilən bu zəiflik SPI modalias uyğunlaşması zamanı çip tutum məlumatlarının düzgün oxunmaması ilə bağlıdır. Problem "mchp23k256" sürücüsündə "of_device_get_match_data()" funksiyasının yalnız Device Tree uyğunluqlarında işləməsi səbəbindən SPI vasitəsilə qoşulan cihazlara təsir edə bilər. Bu vəziyyəti aradan qaldırmaq üçün kernel yeniləməsi tətbiq edilməlidir.
FAQ2
Which Linux kernel component does CVE-2026-68467 affect?
It affects the MTD driver, specifically the "mchp23k256" driver.
What action is required to remediate this vulnerability?
A kernel update must be applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.