Junglewise Threat Intelligence

CVE-2026-53059: Linux Kernel out-of-bounds write in dm log

CVE-2026-53059 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's device-mapper component could allow a local user to cause a system crash or potentially execute unauthorized actions. The issue occurs when managing very large storage volumes, where a mathematical error leads to memory being handled incorrectly. This can result in a complete system failure (kernel panic), impacting the availability of the server and any hosted services.

Technical details

An out-of-bounds write vulnerability exists in the Linux kernel's device-mapper (dm) log component. In create_log_context(), the region_count variable is declared as a 32-bit unsigned integer, while the dm_sector_div_up() function returns a 64-bit sector_t. When a target has a sufficiently large length and small region size, the result exceeds UINT_MAX and is truncated. This truncated value results in undersized memory allocations for clean_bits, sync_bits, and recovering_bits. Subsequent operations (log_set_bit, log_clear_bit, log_test_bit) use the original untruncated indices, leading to out-of-bounds writes to kernel heap memory (vmalloc). This can be triggered locally via dmsetup and results in a kernel crash or potential privilege escalation. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to 44ab8875ae4a2842bde2d756bed195d375e0debb

Timeline

  • 2026-03-05: other: Vulnerability fixed in source code
  • 2026-06-24: disclosed: CVE published

References

Related threats