๐Ÿ” CVE Alert

CVE-2026-89559

HIGH 7.8

libnvdimm/labels: Prevent integer overflow in __nd_label_validate()

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() The on-media namespace index field nslot is a u32 read from the DIMM label storage area. __nd_label_validate() bounds it against the config area size, but sizeof_namespace_label() returns unsigned, so the product nslot * label_size is evaluated in 32-bit and wraps modulo 2^32 before the comparison. A crafted nslot passes the bound and is then used as the loop trip count in nd_label_data_init(), whose memset() walks off the end of the config_size buffer: an out-of-bounds write. The field is not trusted -- it comes from the medium, or from userspace via ND_CMD_SET_CONFIG_DATA. Evaluate the product in 64-bit so the bound check is exact; conforming labels are unaffected. The check was safe when introduced by commit 4a826c83db4e ("libnvdimm: namespace indices: read and validate"): it multiplied by sizeof(struct nd_namespace_label), a size_t, so on a 64-bit build the product did not wrap. Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label definitions") narrowed it to 32 bits when the label size became a runtime value read via sizeof_namespace_label().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
564e871aa66f548a947b23808d3140f326381f0c < b4975f2ff6c82adc24ae547f029f82530ba43cfe 564e871aa66f548a947b23808d3140f326381f0c < 6030597ec683d1e5b46445f888bb5c7776b5a0c4 564e871aa66f548a947b23808d3140f326381f0c < 1c391696d2791f82ae462e11da9a0d96f90b240c 564e871aa66f548a947b23808d3140f326381f0c < 93967bfb17dab66642c57e609c99e1a91fe11278 564e871aa66f548a947b23808d3140f326381f0c < e057efcc9c71d90099d9ee00bed0748d0e9fd586 564e871aa66f548a947b23808d3140f326381f0c < 09e649117c54b7e1c004f22eaa19efbadd9ac856 564e871aa66f548a947b23808d3140f326381f0c < 69a734359639fca16a0dd73ab17a34943e76c68b 564e871aa66f548a947b23808d3140f326381f0c < 037770686126155eafc44501312989e2837b9659
Linux / Linux
4.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b4975f2ff6c82adc24ae547f029f82530ba43cfe git.kernel.org: https://git.kernel.org/stable/c/6030597ec683d1e5b46445f888bb5c7776b5a0c4 git.kernel.org: https://git.kernel.org/stable/c/1c391696d2791f82ae462e11da9a0d96f90b240c git.kernel.org: https://git.kernel.org/stable/c/93967bfb17dab66642c57e609c99e1a91fe11278 git.kernel.org: https://git.kernel.org/stable/c/e057efcc9c71d90099d9ee00bed0748d0e9fd586 git.kernel.org: https://git.kernel.org/stable/c/09e649117c54b7e1c004f22eaa19efbadd9ac856 git.kernel.org: https://git.kernel.org/stable/c/69a734359639fca16a0dd73ab17a34943e76c68b git.kernel.org: https://git.kernel.org/stable/c/037770686126155eafc44501312989e2837b9659