Executive brief
A vulnerability was identified in the Linux kernel's block layer, which manages how data is moved between memory and storage devices. An error in how the system tracks data integrity information could lead to the system reading incorrect memory locations during data transfers. This could potentially result in system instability or unauthorized access to small amounts of data in memory.
Technical details
A vulnerability exists in the Linux kernel block layer within 'block/bio-integrity.c'. The function 'bio_integrity_copy_user()' incorrectly overwrites 'bip_vcnt' with 'nr_vecs', which can violate the constraint 'bip_vcnt <= bip_max_vcnt'. During WRITE operations, this causes gap-merge checks in 'block/blk.h' to perform an out-of-bounds read past the 'bip_vec[]' flexible array. During READ operations, the system may read from a saved user buffer instead of the intended bounce buffer. This issue was introduced by incorrect logic intended for split propagation. Patches have been released for various stable kernel branches including 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux Kernel 6.11, 6.12.92, 6.18.34, 7.0.11
Timeline
- 2026-05-11: disclosed: Initial patch submitted by David Carlier
- 2026-06-01: patched: Patch committed to stable trees
- 2026-07-19: advisory: CVE published in NVD dataset