๐Ÿ” CVE Alert

CVE-2026-68145

UNKNOWN 0.0

iomap: fix out-of-bounds bitmap_set() with zero-length range

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap_set() with zero-length range ifs_set_range_dirty() and ifs_set_range_uptodate() compute last_blk as (off + len - 1) >> i_blkbits. When off is 0 and len is 0, the unsigned subtraction underflows to SIZE_MAX, producing a huge last_blk and nr_blks value that causes bitmap_set() to write far beyond the ifs->state allocation. Regarding ifs_set_range_uptodate(), it is temporarily safe because len cannot be passed in as 0. However, for ifs_set_range_dirty() this is reachable from __iomap_write_end(): when copy_folio_from_iter_atomic() returns 0 (e.g. user buffer fault) and the folio is already uptodate, the guard at the top of __iomap_write_end() does not trigger because !folio_test_uptodate() is false, and iomap_set_range_dirty() is called with copied == 0. Add a !len guard to both functions before the computation, so that a zero-length range is a no-op.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4ce02c67972211be488408c275c8fbf19faf29b3 < fb4fad9105c88b1d82f1b3c39e3b6abea8249af6 4ce02c67972211be488408c275c8fbf19faf29b3 < 7037e7bdcd26f46c080b8ce307dee5cb471c4b7c 4ce02c67972211be488408c275c8fbf19faf29b3 < c5b6a48a8a716a7730e39af1cad083dc4ec955ce 4ce02c67972211be488408c275c8fbf19faf29b3 < 9c7d8f7c8994c790fca501dc45ce66e7356cbe05
Linux / Linux
6.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fb4fad9105c88b1d82f1b3c39e3b6abea8249af6 git.kernel.org: https://git.kernel.org/stable/c/7037e7bdcd26f46c080b8ce307dee5cb471c4b7c git.kernel.org: https://git.kernel.org/stable/c/c5b6a48a8a716a7730e39af1cad083dc4ec955ce git.kernel.org: https://git.kernel.org/stable/c/9c7d8f7c8994c790fca501dc45ce66e7356cbe05