Executive brief
A vulnerability in the Linux kernel's block layer could allow a local user to cause a system crash or instability. The issue occurs when the system calculates storage device parameters, where a mathematical overflow can lead to incorrect memory handling. This affects various Linux-based systems, including industrial controllers from Siemens, potentially impacting operational availability.
Technical details
An integer overflow vulnerability exists in the Linux kernel block layer within the blk_stack_limits() function in block/blk-settings.c. The vulnerability is caused by shifting the 'chunk_sectors' value by 9 bits to convert it to bytes for a alignment check against 'physical_block_size'. On systems with large chunk sizes, this left-shift can overflow an unsigned integer, causing the alignment check to fail or behave unpredictably. An attacker with local access could potentially exploit this to cause a denial-of-service (system crash). The fix changes the logic to perform the modulo check using sector units instead of byte units to avoid the overflow. Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel All versions prior to the August 2025 patches
- Siemens SIMATIC CN 4100 prior to V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and V3.1.6
Timeline
- 2025-07-29: disclosed: Initial patch submission by John Garry
- 2025-08-20: patched: Patch committed to stable kernel tree
- 2025-09-12: advisory: CVE published
References
- https://git.kernel.org/stable/c/14beeef4aafecc8a41de534e31fb5be94739392f
- https://git.kernel.org/stable/c/31f2f080898e50cbf2bae62d35f9f2a997547b38
- https://git.kernel.org/stable/c/3b9d69f0e68aa6b0acd9791c45d445154a8c66e9
- https://git.kernel.org/stable/c/418751910044649baa2b424ea31cce3fc4dcc253
- https://git.kernel.org/stable/c/448dfecc7ff807822ecd47a5c052acedca7d09e8
- https://git.kernel.org/stable/c/46aa80ef49594ed7de685ecbc673b291e9a2c159
- https://git.kernel.org/stable/c/5e276e6ff9aacf8901b9c3265c3cdd2568c9fff2