Executive brief
A vulnerability in the Linux kernel's Advanced Disc Filing System (ADFS) could allow a system crash or memory corruption when a specially crafted disk image is mounted. ADFS is a legacy file system used primarily for compatibility with older Acorn computers. An attacker with physical access or the ability to mount a malicious disk image could exploit this to disrupt system operations.
Technical details
An out-of-bounds write vulnerability exists in the Linux kernel's fs/adfs component due to insufficient validation of the 'nzones' field in the adfs_validate_bblk() function. When a disk record specifies a zero zone count (nzones == 0), adfs_read_map() calls kmalloc_array(0, ...), which returns ZERO_SIZE_PTR. Subsequent operations in adfs_map_layout() attempt to write to an offset of dm[-1], resulting in a write before the allocated buffer. This issue affects new-format ADFS images and was discovered using syzkaller. The fix involves adding a check to reject disk records with a zero zone count during the initial boot block validation (probe time).
Affected products
- Linux Linux Kernel 5.6 to 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2
Timeline
- 2026-03-21: other: Vulnerability fixed in source code by Bae Yeonju
- 2026-06-24: advisory: CVE-2026-52992 published
References
- https://git.kernel.org/stable/c/1586bd2d2fb436a26df20a70e78b000d34a7d159
- https://git.kernel.org/stable/c/1f0ed0f57f0fc87e46fe19a05435c214dc464be2
- https://git.kernel.org/stable/c/33aafd2418a59c96c0389d47ea09026661fa9ec6
- https://git.kernel.org/stable/c/60d82592ac8b5637fbed871381eb0a16df0a492e
- https://git.kernel.org/stable/c/6ff8cca5cdb4f2e0ea6d28ecd78479dd3f221ebc
- https://git.kernel.org/stable/c/a11372a8b1ceaa5e950a84b3b5fbf8228f25e277
- https://git.kernel.org/stable/c/a3fd5dc1c7b0aae947a67dc2e2c037d57557a4de