Description
In the Linux kernel, the following vulnerability has been resolved:

nvdimm/btt: reject an arena whose nfree is below the lane count

The BTT info block's nfree field, the number of reserve free blocks, is
read from the medium without validation. btt_freelist_init() and
btt_rtt_init() size the per-lane freelist[] and rtt[] arrays by nfree,
but the I/O path indexes them by the lane from nd_region_acquire_lane(),
which is bounded by nd_region->num_lanes (ND_MAX_LANES), not by nfree.
A crafted or foreign arena whose nfree is below the lane count makes
freelist[lane]/rtt[lane] run past the allocation: an out-of-bounds write.

btt.rst documents the nlanes = min(nfree, num_cpus) invariant, which the
code does not currently honor: num_lanes is ND_MAX_LANES regardless of
nfree. Reject an arena whose nfree is below num_lanes at discovery,
before the per-lane arrays are allocated, enforcing that invariant.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Write leading to memory corruption
Action: Immediate Patch
AI Analysis

Impact

BTT reads the arena’s nfree field from the medium without validating it. When an arena reports a nfree value that is lower than the number of lanes, the freelist and rtt arrays are allocated too small for the indices used during zone acquisition. This causes an out‑of‑bounds write beyond the allocated buffer, corrupting kernel memory. The resulting corruption can crash the system, corrupt data structures, or provide a foothold for privilege escalation.

Affected Systems

All Linux kernel builds that deploy the NVDIMM/BTT subsystem prior to the commit that added nfree validation are affected. This includes any system that loads the BTT driver and supports persistent memory arenas, regardless of distribution or kernel version, until the patch is applied.

Risk and Exploitability

The CVSS base score of 7.8 indicates serious impact if successful. The EPSS score is less than 1 %, and the vulnerability is not yet listed in CISA’s KEV catalog, meaning no known active exploitation in the wild. However, the vulnerability can be only exercised when a malicious or improperly configured NVDIMM device is presented to the running kernel, so a local or privileged attacker with access to the hardware can trigger the out‑of‑bounds write.

Generated by OpenCVE AI on September 18, 2026 at 07:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Linux kernel that incorporates the patch for BTT nfree validation.
  • If an upgrade is not immediately possible, disable the NVDIMM or BTT driver with a kernel module blacklist or a boot parameter so the subsystem does not load.
  • When BTT support must remain active, enforce validation of NVDIMM metadata so that any arena whose nfree value is less than the lane count is rejected before allocation.
  • Verify that the device firmware does not supply invalid nfree values by using trusted hardware or vendor‑approved NVDIMM modules.

Generated by OpenCVE AI on September 18, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below the lane count The BTT info block's nfree field, the number of reserve free blocks, is read from the medium without validation. btt_freelist_init() and btt_rtt_init() size the per-lane freelist[] and rtt[] arrays by nfree, but the I/O path indexes them by the lane from nd_region_acquire_lane(), which is bounded by nd_region->num_lanes (ND_MAX_LANES), not by nfree. A crafted or foreign arena whose nfree is below the lane count makes freelist[lane]/rtt[lane] run past the allocation: an out-of-bounds write. btt.rst documents the nlanes = min(nfree, num_cpus) invariant, which the code does not currently honor: num_lanes is ND_MAX_LANES regardless of nfree. Reject an arena whose nfree is below num_lanes at discovery, before the per-lane arrays are allocated, enforcing that invariant.
Title nvdimm/btt: reject an arena whose nfree is below the lane count
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:43.493Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89965

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:07.033

Modified: 2026-09-16T15:18:20.830

Link: CVE-2026-89965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer