Description
In the Linux kernel, the following vulnerability has been resolved:

dm-io: clone the source bio instead of copying its biovec

For DM_IO_BIO requests, do_region() built each destination bio by walking
the source bio's biovec and re-adding the pages one at a time, tracking
the remaining transfer in sectors. The vector lengths are byte granular
and need not be sector aligned (e.g. a misaligned O_DIRECT buffer split
across pages), so the sector-based accounting could lose a sub-sector
fragment: to_sector() truncated the remainder and the outer loop spun
forever submitting empty bios, hanging the I/O.

There is no need to rebuild the biovec at all. The destination reads into
(or writes from) exactly the same pages as the source bio, so the bio can
simply clone the source's biovec with bio_alloc_clone() and remap it to
the target device. The clone inherits the source's iterator and alignment,
and the block layer splits it to the target's limits on submission, so the
whole region maps to a single cloned bio with no manual page copying or
sector accounting.

This removes the per-page copy path (and its open-coded bvec dpages
helpers) for bio-backed I/O and fixes the hang on misaligned direct I/O to
a dm-mirror device. Page-list, vma and kmem sources keep the existing copy
path.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (I/O hang)
Action: Patch
AI Analysis

Impact

The vulnerability lies in the Linux kernel’s dm‑io subsystem, where the do_region() routine incorrectly rebuilds destination bio structures for DM_IO_BIO requests by iterating over each page of the source bio and performing sector‑based accounting. When a direct I/O buffer is misaligned, the sector conversion discards a sub‑sector fragment, causing an infinite loop that submits empty bio requests. This results in an I/O hang that stalls operations on the affected DM_i‑mirror device, preventing legitimate processes from accessing the block device until the kernel is restarted or the device is removed. The fix removes the manual page copy path and simply clones the source bio’s biovec with bio_alloc_clone, eliminating the loop. The flaw applies to any Linux kernel binary that includes the device‑mapper dm‑mirror target and the unstable dm‑io implementation. Because the description does not list a specific kernel version, all kernels shipping with the unpatched code are potentially affected. The relation is captured by the generic CPE for the Linux kernel. The CVSS score of 4.1 indicates a low‑severity denial‑of‑service impact confined to the I/O subsystem. The EPSS score is less than 1 %, suggesting a very low likelihood of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to issue misaligned direct I/O requests to a dm‑mirror target, which normally requires local execution or higher privilege. Thus the attack surface is limited to environments where such I/O operations are permitted, and the exploitation path is generally restricted to local or privileged users.

Affected Systems

The affected product is the Linux kernel integral to operating systems that use the device‑mapper dm‑mirror target and the dm‑io subsystem. All kernel releases that contain the unpatched code are potentially affected, and no specific version range is listed in the CNA data.

Risk and Exploitability

Because the flaw manifests as an infinite loop of empty BIO submissions when a misaligned direct‑I/O buffer is used with a dm‑mirror target, the primary consequence is a local denial of service that stalls I/O operations. The CVSS score of 4.1 reflects this low‑severity impact. The EPSS score of less than 1 % indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to issue misaligned O_DIRECT requests to a dm‑mirror device, generally requiring local or privileged execution. Thus the risk to systems exposed to such I/O patterns is low but could affect mission‑critical applications if the kernel is unpatched.

Generated by OpenCVE AI on September 15, 2026 at 21:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the dm‑io bio cloning patch or backport the commit from the upstream source repository.
  • If an immediate update is not possible, avoid misaligned O_DIRECT operations on dm‑mirror targets by using sector‑aligned buffers or disabling O_DIRECT options, or consider moving the mirror to a non‑mirrored device while the system is running the patched kernel.
  • Continuously monitor system logs for signs of repeated empty BIO submissions or I/O hangs that might indicate exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-io: clone the source bio instead of copying its biovec For DM_IO_BIO requests, do_region() built each destination bio by walking the source bio's biovec and re-adding the pages one at a time, tracking the remaining transfer in sectors. The vector lengths are byte granular and need not be sector aligned (e.g. a misaligned O_DIRECT buffer split across pages), so the sector-based accounting could lose a sub-sector fragment: to_sector() truncated the remainder and the outer loop spun forever submitting empty bios, hanging the I/O. There is no need to rebuild the biovec at all. The destination reads into (or writes from) exactly the same pages as the source bio, so the bio can simply clone the source's biovec with bio_alloc_clone() and remap it to the target device. The clone inherits the source's iterator and alignment, and the block layer splits it to the target's limits on submission, so the whole region maps to a single cloned bio with no manual page copying or sector accounting. This removes the per-page copy path (and its open-coded bvec dpages helpers) for bio-backed I/O and fixes the hang on misaligned direct I/O to a dm-mirror device. Page-list, vma and kmem sources keep the existing copy path.
Title dm-io: clone the source bio instead of copying its biovec
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:45.364Z

Reserved: 2026-09-11T19:38:34.728Z

Link: CVE-2026-89578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:42.000

Modified: 2026-09-11T20:19:42.000

Link: CVE-2026-89578

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:45Z

Links: CVE-2026-89578 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')