Description
In the Linux kernel, the following vulnerability has been resolved:

block: validate user space vectors during extraction

The bio-based drivers don't necessarily check the alignment split, and
stacking block drivers don't always handle a misalignment detected after
submitting the bio. Validate user vectors against the device's
dma_alignment as the bio is built from the iov_iter, rejecting
misaligned early with -EINVAL.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel block subsystem contains a flaw where user‑space vectors used to build block I/O structures are not validated for proper alignment. A misaligned vector can cause the underlying driver to interpret data incorrectly, potentially corrupting kernel memory or crashing the system during the I/O operation. This weakness falls under CWE-1288, which deals with improper security checks.

Affected Systems

All Linux kernel releases before the commit referenced in the advisory are affected. The issue applies to any block driver that accepts user‑space I/O vectors, regardless of the vendor, and thus any system running an earlier kernel version is potentially vulnerable.

Risk and Exploitability

Based on the description, it is inferred that an attacker would need to supply a misaligned vector to a block‑device operation, which typically requires local or privileged access to the device. The CVSS score of 4.7, combined with an EPSS score of < 1 %, indicates a low to moderate exploit likelihood, and the vulnerability is not listed in CISA's KEV catalog. If exploited, the kernel could crash or experience memory corruption, leading to a denial of service on the affected machine.

Generated by OpenCVE AI on September 13, 2026 at 04:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the alignment validation patch.
  • If an upgrade cannot be performed immediately, ensure that all user‑space code passing vectors to block operations aligns data to the device's DMA alignment, rejecting misaligned inputs with an error.
  • As a temporary guard, restrict or disable access to any vulnerable block device from untrusted user space until the patch is applied.

Generated by OpenCVE AI on September 13, 2026 at 04:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1288
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: block: validate user space vectors during extraction The bio-based drivers don't necessarily check the alignment split, and stacking block drivers don't always handle a misalignment detected after submitting the bio. Validate user vectors against the device's dma_alignment as the bio is built from the iov_iter, rejecting misaligned early with -EINVAL.
Title block: validate user space vectors during extraction
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:17.636Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:42.797

Modified: 2026-09-13T07:17:24.127

Link: CVE-2026-89584

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:49Z

Links: CVE-2026-89584 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T04:45:18Z

Weaknesses
  • CWE-1288

    Improper Validation of Consistency within Input