Junglewise Threat Intelligence

CVE-2026-90052: Linux kernel dm-integrity buffer overflow with keyed discard

CVE-2026-90052 · Severity: high · CVSS 7.8 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's dm-integrity module, which provides data integrity checking for block device storage, contains a buffer overflow vulnerability in its handling of discarded blocks. When processing discard operations with keyed checksums (using algorithms like HMAC-SHA256), the module writes checksum data beyond the allocated buffer size, potentially corrupting kernel memory. This could lead to kernel crashes or data corruption on systems using encrypted or integrity-checked storage.

Technical details

The vulnerability is a heap buffer overflow in dm-integrity's integrity_metadata function. When computing checksums for discarded blocks, the code incorrectly calculates the maximum number of blocks (max_blocks) that fit in the checksums buffer by dividing the buffer size by tag_size, without accounting for extra_space (the difference between digest size and tag size). When the digest size exceeds tag size (e.g., HMAC-SHA256 digest is 32 bytes but tag is 16 bytes), integrity_sector_checksum writes the full digest past the buffer boundary. For example, a 4 MiB discard can write 16 bytes past the kmalloc'd page. The fix subtracts extra_space from max_size before computing max_blocks, mirroring the logic already used for write operations. This is a local kernel memory corruption issue requiring no network access or privilege escalation.

Affected products

  • Linux Linux Kernel 5.4 and later (introduced in commit 68c5c42567bc)

Timeline

  • 2026-09-17: disclosed
  • 2026-09-01: patched: Fix committed upstream
  • 2026-09-14: patched: Backported to stable kernels

References

Related threats