Description
An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The flaw is an integer overflow or wraparound within the file operation component of Synology DiskStation Manager. When a remote user who is already authenticated submits a specially crafted request, the overflow allows the device to miscalculate a file size or counter and ultimately crash its file service. This results in a limited denial‑of‑service for the affected system. The weakness is identified as CWE‑190, indicating an arithmetic overflow flaw. The impact is confined to availability, not confidentiality or integrity.

Affected Systems

Synology DiskStation Manager is affected in all releases before 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any Synology device running these versions of DSM is vulnerable, regardless of operating system or firmware other than the documented versions.

Risk and Exploitability

The CVSS score is 4.3 and the EPSS score is less than 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Likely attack requires the attacker to have valid authenticated access to the DSM environment, after which the attack can be carried out with a single HTTP request to trigger the overflow. The impact is limited to a temporary service interruption and does not grant further privileges or data access.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update DSM to the latest version that is beyond the affected releases; this removes the integer overflow bug.
  • Revoke or restrict file‑operation permissions for users who do not need them; limiting privileges reduces the attack surface for a remote authenticated user.
  • Monitor system logs and network traffic for unusual file‑operation requests or repeated crashes, and apply additional firewall rules if suspicious activity is detected.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in DSM File Operation Enables Limited Denial-of-Service

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in DSM File Operation Enables Limited Denial-of-Service

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:09:31.972Z

Reserved: 2026-04-14T01:01:14.606Z

Link: CVE-2026-40531

cve-icon Vulnrichment

Updated: 2026-09-18T19:09:23.039Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.357

Modified: 2026-09-18T20:17:15.743

Link: CVE-2026-40531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound