Bug 2532117 (CVE-2026-89574) - CVE-2026-89574 kernel: Linux kernel: dm array out-of-bounds read due to insufficient header validation
Summary: CVE-2026-89574 kernel: Linux kernel: dm array out-of-bounds read due to insuf...
Keywords:
Status: NEW
Alias: CVE-2026-89574
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 20:44 UTC by OSIDB Bzimport
Modified: 2026-09-11 21:04 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 20:44:54 UTC
In the Linux kernel, the following vulnerability has been resolved:

dm array: validate array block headers on read

array_block_check() validates blocknr and csum and nothing else, while
node_check(), next to it, has bounded the structural fields since both
were written. dm_array_cursor_next() takes its loop bound from the
on-disk nr_entries and element_at() is unguarded pointer arithmetic, so
a count larger than the block holds keeps the cursor in one block while
the index grows past it and the read walks off the dm-bufio buffer --
dm_cache_load_mappings() drives it once per cache block at activation.

Check the header against itself: reject a zero value_size, require
max_entries to equal calc_max_entries() for that value_size and block
size, and require nr_entries to fit. Equality rather than an upper bound,
since a count below the real capacity trips BUG_ON() in fill_ablock() and
trim_ablock(). Metadata dm-array writes satisfies all three.


Note You need to log in before you can comment on or make changes to this bug.