Description
In the Linux kernel, the following vulnerability has been resolved:

dm array: reject an array block whose value size is not the caller's

array_block_check() can only compare the header against itself, so a block
with value_size 4 and max_entries 1018 is internally consistent and passes.
dm-cache keeps two arrays -- mappings at 8 bytes and hints at 4 -- and the
roots for both live in the superblock. Point the mappings root at a hint
block and __load_mappings() walks it through an info whose value size is 8,
so element_at() strides 8 bytes over 4-byte entries and reaches offset 8160
of a 4096-byte block.

get_ablock() and __shadow_ablock() are the two places that hold the block
and the caller at once. Reject there when the two value sizes disagree.
Arrays only ever read their own blocks, so this fires on crafted metadata
only.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local kernel memory corruption
Action: Patch immediately
AI Analysis

Impact

The dm array driver in the Linux kernel incorrectly accepts a block whose value_size does not match the caller's expected size, causing an out‑of‑bounds read during array traversal. This flaw can expose parts of kernel memory and lead to kernel memory corruption. The weakness is identified as CWE‑843, inconsistent type usage.

Affected Systems

The vulnerability affects the dm array component of the Linux kernel. All deployments of the Linux kernel that include the device‑mapper array feature are potentially vulnerable until a patch is applied. No specific kernel versions are listed, so the risk applies to any current kernel that implements the device‑mapper array feature.

Risk and Exploitability

The likely attack vector is the modification of dm array metadata on a block device by an attacker with local or privileged access. The CVSS score of 7.8 indicates high severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. As a result, the likelihood of exploitation remains low in environments that use dm array on untrusted metadata, while production systems with strict configuration controls may face even lower risk.

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the official dm array patch.
  • If an update is not immediately available, disable or unload the dm-array module and avoid creating new dm array devices.
  • Limit creation and modification of device‑mapper configuration files to privileged users and enforce strict ownership and permissions.

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is not the caller's array_block_check() can only compare the header against itself, so a block with value_size 4 and max_entries 1018 is internally consistent and passes. dm-cache keeps two arrays -- mappings at 8 bytes and hints at 4 -- and the roots for both live in the superblock. Point the mappings root at a hint block and __load_mappings() walks it through an info whose value size is 8, so element_at() strides 8 bytes over 4-byte entries and reaches offset 8160 of a 4096-byte block. get_ablock() and __shadow_ablock() are the two places that hold the block and the caller at once. Reject there when the two value sizes disagree. Arrays only ever read their own blocks, so this fires on crafted metadata only.
Title dm array: reject an array block whose value size is not the caller's
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:06.500Z

Reserved: 2026-09-11T19:38:34.727Z

Link: CVE-2026-89573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.390

Modified: 2026-09-14T13:19:11.893

Link: CVE-2026-89573

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:41Z

Links: CVE-2026-89573 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')