๐Ÿ” CVE Alert

CVE-2026-89574

HIGH 7.8

dm array: validate array block headers on read

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: dm array: validate array block headers on read array_block_check() validates blocknr and csum and nothing else, while node_check(), next to it, has bounded the structural fields since both were written. dm_array_cursor_next() takes its loop bound from the on-disk nr_entries and element_at() is unguarded pointer arithmetic, so a count larger than the block holds keeps the cursor in one block while the index grows past it and the read walks off the dm-bufio buffer -- dm_cache_load_mappings() drives it once per cache block at activation. Check the header against itself: reject a zero value_size, require max_entries to equal calc_max_entries() for that value_size and block size, and require nr_entries to fit. Equality rather than an upper bound, since a count below the real capacity trips BUG_ON() in fill_ablock() and trim_ablock(). Metadata dm-array writes satisfies all three.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
6513c29f44f2cc970c0e9fecfe5a6526c3e73025 < 67adda7ed5da3e3b64f5b9021a02c21fb374fd9c 6513c29f44f2cc970c0e9fecfe5a6526c3e73025 < b33f76d33aaeacf3baf3370d8d64985169b36600 6513c29f44f2cc970c0e9fecfe5a6526c3e73025 < 9808ddffb4bc659352df3020cd84d9d864820ee5 6513c29f44f2cc970c0e9fecfe5a6526c3e73025 < 2965787723084835b18dfe993cd450ebf5bd4540
Linux / Linux
3.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/67adda7ed5da3e3b64f5b9021a02c21fb374fd9c git.kernel.org: https://git.kernel.org/stable/c/b33f76d33aaeacf3baf3370d8d64985169b36600 git.kernel.org: https://git.kernel.org/stable/c/9808ddffb4bc659352df3020cd84d9d864820ee5 git.kernel.org: https://git.kernel.org/stable/c/2965787723084835b18dfe993cd450ebf5bd4540