๐Ÿ” CVE Alert

CVE-2026-72098

UNKNOWN 0.0

dm-verity: fix buffer overflow in FEC calculation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation There's a buffer overflow in dm-verity-fec: if (neras && *neras <= v->fec->roots) fio->erasures[(*neras)++] = i; This allows *neras to reach roots + 1 (the post-increment pushes it past roots). This value is then passed as no_eras to decode_rs8(). Inside the RS decoder (lib/reed_solomon/decode_rs.c:113-121), the erasure locator polynomial loop writes lambda[j] where j can reach nroots + 1 โ€” one element past the end of lambda[] (which is sized nroots + 1, valid indices 0..nroots). The out-of-bounds write lands on syn[0], corrupting the syndrome buffer.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 5488d3a69d205e28f74f18857b853aa12e778e66 a739ff3f543afbb4a041c16cd0182c8e8d366e70 < f7990c2b0f08b8841fcd2652d1d7002f5994a7a7 a739ff3f543afbb4a041c16cd0182c8e8d366e70 < 31d6e6c0ba8d5a7bd59660035a089307100c5e8e
Linux / Linux
4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5488d3a69d205e28f74f18857b853aa12e778e66 git.kernel.org: https://git.kernel.org/stable/c/f7990c2b0f08b8841fcd2652d1d7002f5994a7a7 git.kernel.org: https://git.kernel.org/stable/c/31d6e6c0ba8d5a7bd59660035a089307100c5e8e