Description
In the Linux kernel, the following vulnerability has been resolved:

dm array: validate array block headers on read

array_block_check() validates blocknr and csum and nothing else, while
node_check(), next to it, has bounded the structural fields since both
were written. dm_array_cursor_next() takes its loop bound from the
on-disk nr_entries and element_at() is unguarded pointer arithmetic, so
a count larger than the block holds keeps the cursor in one block while
the index grows past it and the read walks off the dm-bufio buffer --
dm_cache_load_mappings() drives it once per cache block at activation.

Check the header against itself: reject a zero value_size, require
max_entries to equal calc_max_entries() for that value_size and block
size, and require nr_entries to fit. Equality rather than an upper bound,
since a count below the real capacity trips BUG_ON() in fill_ablock() and
trim_ablock(). Metadata dm-array writes satisfies all three.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read leading to information disclosure or denial of service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel device‑mapper array module performs limited validation in array_block_check, accepting block numbers and checksums while ignoring structural limits on entry counts. When dm_array_cursor_next calculates its loop bound from an on‑disk field that exceeds a block’s actual capacity, element_at performs unchecked pointer arithmetic. This allows a read to traverse beyond the dm‑bufio buffer and access kernel memory or trigger a kernel crash, exposing sensitive data or causing service interruption.

Affected Systems

Linux kernel instances that include the dm‑array module and are running a version prior to the applied patch are affected. The vulnerability is independent of distribution and affects any installation where the dm‑array subsystem is enabled and the kernel code has not been updated to contain the header‑validation fix.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require local or privileged access that can manipulate DM array blocks or load the device‑mapper subsystem. No public exploit has been reported; the attack vector is inferred to be local privilege elevation or direct interaction with the dm‑array interface.

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the dm‑array header‑validation patch.
  • If an upgrade is not possible, disable dm‑array by removing the CONFIG_DM_ARRAY option from the kernel configuration or blacklisting the dm‑array kernel module.
  • For older kernels lacking the fix, apply the upstream patch that adds proper header validation or rebuild the kernel from source with the corrected code.

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm array: validate array block headers on read array_block_check() validates blocknr and csum and nothing else, while node_check(), next to it, has bounded the structural fields since both were written. dm_array_cursor_next() takes its loop bound from the on-disk nr_entries and element_at() is unguarded pointer arithmetic, so a count larger than the block holds keeps the cursor in one block while the index grows past it and the read walks off the dm-bufio buffer -- dm_cache_load_mappings() drives it once per cache block at activation. Check the header against itself: reject a zero value_size, require max_entries to equal calc_max_entries() for that value_size and block size, and require nr_entries to fit. Equality rather than an upper bound, since a count below the real capacity trips BUG_ON() in fill_ablock() and trim_ablock(). Metadata dm-array writes satisfies all three.
Title dm array: validate array block headers on read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:11.485Z

Reserved: 2026-09-11T19:38:34.727Z

Link: CVE-2026-89574

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.517

Modified: 2026-09-13T07:17:23.347

Link: CVE-2026-89574

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:42Z

Links: CVE-2026-89574 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses