Executive brief
A vulnerability in the Linux kernel's device-mapper component could allow a local user to cause a system crash or potentially execute unauthorized actions. The issue occurs when managing very large storage volumes, where a mathematical error leads to memory being handled incorrectly. This can result in a complete system failure (kernel panic), impacting the availability of the server and any hosted services.
Technical details
An out-of-bounds write vulnerability exists in the Linux kernel's device-mapper (dm) log component. In create_log_context(), the region_count variable is declared as a 32-bit unsigned integer, while the dm_sector_div_up() function returns a 64-bit sector_t. When a target has a sufficiently large length and small region size, the result exceeds UINT_MAX and is truncated. This truncated value results in undersized memory allocations for clean_bits, sync_bits, and recovering_bits. Subsequent operations (log_set_bit, log_clear_bit, log_test_bit) use the original untruncated indices, leading to out-of-bounds writes to kernel heap memory (vmalloc). This can be triggered locally via dmsetup and results in a kernel crash or potential privilege escalation. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 44ab8875ae4a2842bde2d756bed195d375e0debb
Timeline
- 2026-03-05: other: Vulnerability fixed in source code
- 2026-06-24: disclosed: CVE published
References
- https://git.kernel.org/stable/c/12bd5b88e91a02785244ff1d20fb157e96e9cdc8
- https://git.kernel.org/stable/c/3ec74da927b4e171a6fc0e77b1188ba4d019af51
- https://git.kernel.org/stable/c/44ab8875ae4a2842bde2d756bed195d375e0debb
- https://git.kernel.org/stable/c/4ec8323b9f0764a14d532b1ae9b87f8a9fecb867
- https://git.kernel.org/stable/c/b455903eed4558982be0811f5b7f44f6bbc4ff57
- https://git.kernel.org/stable/c/c20e36b7631d83e7535877f08af8b0af72c44b1a
- https://git.kernel.org/stable/c/d4ac87567f86a55c3c92e9a5144dcd943a9772a1