Junglewise Threat Intelligence

CVE-2026-64232: Linux Kernel denial of service in block integrity segment mapping

CVE-2026-64232 · Severity: info · CVSS 5.5 · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's storage management system could allow a local user to cause a system crash. The issue occurs when the system handles specific types of data integrity checks across complex storage configurations, such as those using multiple paths to NVMe drives. This could lead to a denial-of-service condition, impacting the availability of the affected server or workstation.

Technical details

A vulnerability exists in the Linux kernel block layer within `blk_insert_cloned_request()`. The root cause is a failure to recompute `nr_integrity_segments` when a request is cloned and passed to a bottom queue that may have more restrictive segment limits (such as `virt_boundary_mask` or `max_segment_size`) than the original top queue. When the recomputed segment count exceeds the cached count inherited during cloning, the kernel triggers a `BUG_ON` in `blk_rq_map_integrity_sg()` during dispatch. This issue is particularly prevalent in stacked storage setups like dm-multipath over nvme-rdma. The fix involves recomputing the integrity segments against the bottom queue and rejecting requests that exceed the hardware's maximum limits.

Affected products

  • Linux Linux Kernel 6.12.92 and earlier versions starting from 6.12

Timeline

  • 2026-05-11: other: Patch submitted by developer
  • 2026-07-24: disclosed: CVE published

References

Related threats