Description
In the Linux kernel, the following vulnerability has been resolved:

block: validate user space vectors during extraction

The bio-based drivers don't necessarily check the alignment split, and
stacking block drivers don't always handle a misalignment detected after
submitting the bio. Validate user vectors against the device's
dma_alignment as the bio is built from the iov_iter, rejecting
misaligned early with -EINVAL.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel block subsystem fails to validate that user‑space I/O vectors are aligned to the device’s DMA. When a caller supplies a misaligned vector, the kernel previously accepted the vector and later detected the misalignment during bio handling, which could lead to data corruption or kernel panic. The fix adds input validation that checks the alignment against the device’s dma_alignment during bio construction, rejecting misaligned vectors early with an -EINVAL error.

Affected Systems

All Linux kernel releases prior to the commit that introduced the alignment validation are vulnerable. The flaw exists in every block driver that accepts user‑space vectors, so any system running an earlier kernel version, regardless of vendor or distribution, is affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score of < 1 % suggests a low probability of exploitation. Based on the description, it is inferred that an attacker who can invoke block operations from user space could provide a misaligned I/O vector, causing the kernel to reject the request with -EINVAL. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 21:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the alignment validation patch.
  • If an update is not immediately possible, ensure that all user‑space applications that pass I/O vectors to block devices validate vector alignment against the device’s DMA alignment and reject misaligned inputs before invoking kernel block operations.
  • As a temporary countermeasure, restrict user space access to vulnerable block devices by adjusting device node permissions or disabling the devices until the kernel patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1288
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: block: validate user space vectors during extraction The bio-based drivers don't necessarily check the alignment split, and stacking block drivers don't always handle a misalignment detected after submitting the bio. Validate user vectors against the device's dma_alignment as the bio is built from the iov_iter, rejecting misaligned early with -EINVAL.
Title block: validate user space vectors during extraction
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:17.636Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:42.797

Modified: 2026-09-13T07:17:24.127

Link: CVE-2026-89584

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:49Z

Links: CVE-2026-89584 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-1288

    Improper Validation of Consistency within Input