Description
In the Linux kernel, the following vulnerability has been resolved:

dm-integrity: fix buffer overflow with keyed discard

Since commit 68c5c42567bc ("dm-integrity: replace forgeable discard
filler with a keyed sector marker"), integrity_metadata computes a
checksum for every discarded block into the "checksums" buffer.
integrity_sector_checksum always writes the whole digest. So if the tag
size is smaller than the digest size, the checksum of the last block
that fits into the buffer is written past the end of it. For example,
with hmac(sha256) and tag size 16, a 4MiB discard writes 16 bytes past
the kmalloc'ed page.

Fix this by subtracting extra_space from the buffer size when computing
max_blocks, like we do for writes.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in the Linux kernel’s dm-integrity subsystem arises from a buffer overrun caused by miscalculating buffer space when computing checksums for discarded blocks that use keyed sector markers. A discard operation can write beyond the bounds of an allocated page, resulting in memory corruption that may enable an attacker to execute arbitrary code within kernel context. The overflow occurs when the tag size is smaller than the digest size, with the checksum of the last block written past the allocated buffer.

Affected Systems

The flaw affects all Linux kernel builds that use the dm-integrity module prior to the patch that applied commit 68c5c42567bc. It applies to any system where the dm-integrity target device is enabled, regardless of distribution, as the vulnerability is identified at the kernel level. No specific vendor or product versions are listed, so any older kernel using dm-integrity is potentially impacted.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity; the buffer overflow nature indicates a high likelihood of privilege escalation or arbitrary code execution. The EPSS score is less than 1%, indicating a low estimate of exploitation probability at this time, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires a discard operation on a dm-integrity-enabled device, the likely attack vector is local exploitation through privileged or root-level access to the block device.

Generated by OpenCVE AI on September 20, 2026 at 04:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the dm-integrity buffer overflow fix (commit 68c5c42567bc).
  • If an immediate kernel upgrade is not possible, disable the dm-integrity module or the discard feature for devices that use it.
  • If disabling is infeasible, monitor kernel logs for messages indicating discarded block checksum writes and restrict or revoke discard operations on critical devices.

Generated by OpenCVE AI on September 20, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed discard Since commit 68c5c42567bc ("dm-integrity: replace forgeable discard filler with a keyed sector marker"), integrity_metadata computes a checksum for every discarded block into the "checksums" buffer. integrity_sector_checksum always writes the whole digest. So if the tag size is smaller than the digest size, the checksum of the last block that fits into the buffer is written past the end of it. For example, with hmac(sha256) and tag size 16, a 4MiB discard writes 16 bytes past the kmalloc'ed page. Fix this by subtracting extra_space from the buffer size when computing max_blocks, like we do for writes.
Title dm-integrity: fix buffer overflow with keyed discard
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:46.592Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:53.610

Modified: 2026-09-18T18:17:39.910

Link: CVE-2026-90052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:15:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow