๐Ÿ” CVE Alert

CVE-2026-68478

UNKNOWN 0.0

memstick: ms_block: reject a card that reports too many blocks

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a card that reports too many blocks msb_ftl_initialize() computes the zone count from the card block count with no bound: msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE; ... for (i = 0; i < msb->zone_count; i++) msb->free_block_count[i] = MS_BLOCKS_IN_ZONE; msb->block_count is a card value. msb_read_boot_blocks() reads number_of_blocks from the card boot page and byte swaps it. free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the valid indices are 0 to 15. The init loop above indexes it by zone_count. msb_mark_block_used() and msb_mark_block_unused() index it by pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES * MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past free_block_count[] and corrupts struct msb_data. A larger count runs the init loop past the end too. A real Memory Stick has at most 16 zones. So it has at most 8192 blocks. msb_ftl_initialize() now rejects a card that reports more than MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < a4b9961efe8640f50800811b4a2b2046b3dc2ccc 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < 8937b11f1c3896e066c3fb07387ba17bc8c50b8a 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < f1c675ecf6e5ad02722f0019f729d8bb588d502e 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < d5db3439ee8d1c165a09a47e984c4ba508c130df 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < b86666ac4009a252501cc17242582a7ec9ed976e 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < 39151f0708c84221e94cdd6aa070aba5d7cb1c01 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < 47f0c7d856c67c9935546d2644f18c0d0131b449 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 < 718178f524b98bc920d74bc771aed823c8b81425
Linux / Linux
3.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc git.kernel.org: https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a git.kernel.org: https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e git.kernel.org: https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df git.kernel.org: https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e git.kernel.org: https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01 git.kernel.org: https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449 git.kernel.org: https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425