Junglewise Threat Intelligence

CVE-2026-52992: Linux Kernel out-of-bounds write in ADFS file system

CVE-2026-52992 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Advanced Disc Filing System (ADFS) could allow a system crash or memory corruption when a specially crafted disk image is mounted. ADFS is a legacy file system used primarily for compatibility with older Acorn computers. An attacker with physical access or the ability to mount a malicious disk image could exploit this to disrupt system operations.

Technical details

An out-of-bounds write vulnerability exists in the Linux kernel's fs/adfs component due to insufficient validation of the 'nzones' field in the adfs_validate_bblk() function. When a disk record specifies a zero zone count (nzones == 0), adfs_read_map() calls kmalloc_array(0, ...), which returns ZERO_SIZE_PTR. Subsequent operations in adfs_map_layout() attempt to write to an offset of dm[-1], resulting in a write before the allocated buffer. This issue affects new-format ADFS images and was discovered using syzkaller. The fix involves adding a check to reject disk records with a zero zone count during the initial boot block validation (probe time).

Affected products

  • Linux Linux Kernel 5.6 to 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2

Timeline

  • 2026-03-21: other: Vulnerability fixed in source code by Bae Yeonju
  • 2026-06-24: advisory: CVE-2026-52992 published

References

Related threats