Executive brief
The Linux kernel's Minix filesystem implementation fails to prevent integer overflow when validating the superblock of a crafted Minix v3 image. An attacker can create a malicious filesystem image that, when mounted, causes the kernel to crash and become unavailable. This impacts any system that allows mounting untrusted Minix filesystems, such as shared hosting environments or systems processing user-supplied disk images.
Technical details
The vulnerability is an integer overflow in the minix_blocks_needed() function, which uses DIV_ROUND_UP() macro in unsigned int arithmetic to calculate required bitmap block counts. When s_ninodes or s_zones values are set near UINT_MAX on a Minix v3 image, the addition inside DIV_ROUND_UP() wraps to zero, causing invalid zero bitmap-block counts to pass superblock validation. Subsequently, minix_fill_super() attempts to dereference s_imap[0] or s_zmap[0] without allocated bitmap buffers, triggering a kernel panic. The fix replaces DIV_ROUND_UP() with DIV_ROUND_UP_POW2() which performs the division before adding the round-up term, preventing overflow when the divisor (blocksize * 8) is a power of two. Attack vector is local via crafted filesystem image; no user privileges required beyond filesystem mount capability.
Affected products
- Linux Linux kernel 2.6.11 through 6.11+ (and later major versions); Minix filesystem driver support across all affected kernel versions
Timeline
- 2026-08-15: disclosed: CVE-2026-72369 published
- 2026-06-18: patched: Fix committed to Linux kernel stable tree (commit 8a29e60e2176b02e04f8737c8b32b696230eb0c5)
- 2026-07-24: other: Fix merged to stable kernel branches by Greg Kroah-Hartman