Description
In the Linux kernel, the following vulnerability has been resolved:

dm-verity: make error counter atomic

The error counter "v->corrupted_errs" was not atomic, thus it could be
subject to race conditions. The call to
dm_audit_log_target("max-corrupted-errors") may be skipped due to the
races.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel module dm‑verity tracks corrupted block errors using a counter (v->corrupted_errs). When this counter is accessed concurrently without atomicity, multiple threads can modify it simultaneously, creating a race condition. This flaw can cause the audit logging function dm_audit_log_target("max-corrupted-errors") to be invoked inconsistently or omitted entirely, so integrity violations may go unlogged. The vulnerability does not allow code execution or privilege escalation, but it weakens confidence in audit trails that rely on dm‑verity reporting.

Affected Systems

All Linux kernel releases that include dm‑verity before the atomic counter change (identified by commit 089e05b644d5aa786c21af467c80b24d691becb1) are affected. This includes the generic kernel and any derivatives that have not incorporated the fix.

Risk and Exploitability

The likely attack vector is local; the description does not explicitly state it but the concurrent use of the dm‑verity counter implies that only a process with sufficient privileges to trigger a race condition on a dm‑verity mapped device could do so. The CVSS score is 5.5, indicating a moderate severity, while the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploit campaigns. The primary risk lies in degraded integrity monitoring rather than direct compromise.

Generated by OpenCVE AI on August 18, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel version that includes the atomic counter change (commit 089e05b644d5aa786c21af467c80b24d691becb1 or later).
  • Confirm that device‑mapper audit logging is enabled so that dm‑verity corruption events are captured and monitored.
  • If a kernel update cannot be applied immediately, consider disabling dm‑verity on devices where audit logging is critical and supplement with alternative integrity verification mechanisms.

Generated by OpenCVE AI on August 18, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 13:15:00 +0000


Tue, 18 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-663
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-verity: make error counter atomic The error counter "v->corrupted_errs" was not atomic, thus it could be subject to race conditions. The call to dm_audit_log_target("max-corrupted-errors") may be skipped due to the races.
Title dm-verity: make error counter atomic
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-23T12:46:48.390Z

Reserved: 2026-08-09T03:40:39.905Z

Link: CVE-2026-72096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:23.680

Modified: 2026-08-23T13:16:40.040

Link: CVE-2026-72096

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72096 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T05:45:03Z

Weaknesses
  • CWE-663

    Use of a Non-reentrant Function in a Concurrent Context