Description
In the Linux kernel, the following vulnerability has been resolved:

dm raid1: reserve space for NUL-terminator in build_constructor_string()

Reserve space for the termination NUL after the maximum 20 decimal
digits of a long long value to avoid buffer overflow in sprintf().
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local buffer overflow leading to memory corruption
Action: Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s dm raid1 module where a buffer overflow can happen while constructing a string representation of a 64‑bit value. The flaw arises because the code reserves only space for the decimal digits but does not allocate an additional byte for the terminating NUL, causing a possible overflow in sprintf. This overflow could overwrite adjacent memory, potentially corrupting kernel data structures and leading to crashes or arbitrary code execution if the attacker can influence the string.

Affected Systems

Affected systems are Linux kernels that include the dm raid1 device manager before the fix is integrated. This includes all current and older releases that still ship the vulnerable code. The CNA vendor list notes Linux:Linux, and the CPE indicates linux_kernel. No specific versions were enumerated, so any kernel lacking the patch is vulnerable.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no widespread exploitation has been documented. Based on the description, the attack vector is local: an attacker would need to provide a malicious dm raid1 configuration or load a module with crafted parameters, which typically requires root or kernel privilege on the target system.

Generated by OpenCVE AI on September 15, 2026 at 22:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the dm raid1 fix.
  • Reboot the system to load the updated module.
  • If the dm raid1 module is not required, disable or remove it to reduce exposure.

Generated by OpenCVE AI on September 15, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-170
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm raid1: reserve space for NUL-terminator in build_constructor_string() Reserve space for the termination NUL after the maximum 20 decimal digits of a long long value to avoid buffer overflow in sprintf().
Title dm raid1: reserve space for NUL-terminator in build_constructor_string()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:07.555Z

Reserved: 2026-09-11T19:38:34.727Z

Link: CVE-2026-89575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.643

Modified: 2026-09-14T13:19:12.053

Link: CVE-2026-89575

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:43Z

Links: CVE-2026-89575 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses
  • CWE-170

    Improper Null Termination