Description
In the Linux kernel, the following vulnerability has been resolved:

libnvdimm/labels: Prevent integer overflow in __nd_label_validate()

The on-media namespace index field nslot is a u32 read from the DIMM
label storage area. __nd_label_validate() bounds it against the config
area size, but sizeof_namespace_label() returns unsigned, so the product
nslot * label_size is evaluated in 32-bit and wraps modulo 2^32 before
the comparison. A crafted nslot passes the bound and is then used as the
loop trip count in nd_label_data_init(), whose memset() walks off the end
of the config_size buffer: an out-of-bounds write.

The field is not trusted -- it comes from the medium, or from userspace
via ND_CMD_SET_CONFIG_DATA. Evaluate the product in 64-bit so the bound
check is exact; conforming labels are unaffected.

The check was safe when introduced by commit 4a826c83db4e ("libnvdimm:
namespace indices: read and validate"): it multiplied by sizeof(struct
nd_namespace_label), a size_t, so on a 64-bit build the product did not
wrap. Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label
definitions") narrowed it to 32 bits when the label size became a runtime
value read via sizeof_namespace_label().
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch
AI Analysis

Impact

In the libnvdimm subsystem of the in the __nd_label_validate() function. The function multiplies the on‑media namespace index (nslot), a 32‑bit value read from the DIMM label or supplied via ND_CMD_SET_CONFIG_DATA, by the runtime label size using 32‑bit arithmetic. This product can wrap around modulo 2^{32} before the bound check is performed. A crafted nslot value can therefore pass the bounds test and become the loop counter in nd_label_data_init(). The memset used there walks past the end of the configuration buffer, resulting in an out‑of‑bounds write and corruption of kernel memory.

Affected Systems

All Linux kernel builds that include the libnvdimm subsystem before the 64‑bit bound check introduced in commit 564e871aa66f are potentially affected. Kernel configurations that enable NVDIMM handling are at risk; any build without the commit may be vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA KEV. Exploitation would likely require local or privileged access to supply a crafted ND_CMD_SET_CONFIG_DATA request or to manipulate the on‑media label. Based on the description, it is inferred that an attacker can abuse the ND_CMD_SET_CONFIG_DATA interface to inject a malicious index, triggering the integer overflow and ensuing out‑of‑bounds write.

Generated by OpenCVE AI on September 15, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest kernel version that includes the 64‑bit bound check introduced by commit 564e871aa66f.
  • If an update is not yet available, disable libnvdimm support in the kernel configuration (e.g., set CONFIG_NVDIMM=n) to eliminate the vulnerable code.
  • Limit access to the ND_CMD_SET_CONFIG_DATA interface to privileged users and ensure NVDIMM configuration is only performed by trusted administrators.

Generated by OpenCVE AI on September 15, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() The on-media namespace index field nslot is a u32 read from the DIMM label storage area. __nd_label_validate() bounds it against the config area size, but sizeof_namespace_label() returns unsigned, so the product nslot * label_size is evaluated in 32-bit and wraps modulo 2^32 before the comparison. A crafted nslot passes the bound and is then used as the loop trip count in nd_label_data_init(), whose memset() walks off the end of the config_size buffer: an out-of-bounds write. The field is not trusted -- it comes from the medium, or from userspace via ND_CMD_SET_CONFIG_DATA. Evaluate the product in 64-bit so the bound check is exact; conforming labels are unaffected. The check was safe when introduced by commit 4a826c83db4e ("libnvdimm: namespace indices: read and validate"): it multiplied by sizeof(struct nd_namespace_label), a size_t, so on a 64-bit build the product did not wrap. Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label definitions") narrowed it to 32 bits when the label size became a runtime value read via sizeof_namespace_label().
Title libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:00.097Z

Reserved: 2026-09-11T19:38:34.724Z

Link: CVE-2026-89559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:39.673

Modified: 2026-09-14T13:19:10.937

Link: CVE-2026-89559

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:31Z

Links: CVE-2026-89559 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses