Description
In the Linux kernel, the following vulnerability has been resolved:

dm-integrity: replace forgeable discard filler with a keyed sector marker

The discard-block check in dm_integrity_rw_tag() treats a stored tag
of all 0xf6 bytes (DISCARD_FILLER) as proof a block was discarded and
skips HMAC verification. allow_discards is only accepted in
dm-integrity's standalone mode. An attacker with raw write access to
the backing device, but without the integrity key, can stamp any block
with an all-0xf6 tag and have it served as authentic.

Add a new "allow_discards_keyed" target argument that marks discarded
blocks with a keyed checksum of (salt || sector) instead, computed by
integrity_discard_checksum().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Compromise
Action: Patch
AI Analysis

Impact

The dm-integrity subsystem in the Linux kernel contained a flaw that allowed a user with raw write access to a backing device to forge a discard‑block tag. By writing a block whose tag consists entirely of 0xf6 bytes, the kernel treats the block as ‘discarded’ and skips HMAC verification, even though the attacker does not possess the integrity key. This bypass undermines the integrity protection mechanism, allowing arbitrary data to be accepted as authenticated.

Affected Systems

All Linux kernel implementations that include the dm-integrity module and which accept the allow_discards flag in standalone mode are affected. Because no concrete version range is listed, any kernel that has not incorporated the patch referenced by the commit series is vulnerable. The flaw applies to the generic Linux image and to distributions that ship with dm-integrity enabled.

Risk and Exploitability

The EPSS score of less than 1% and the lack of a listing in the CISA KEV catalog indicate that current exploitation is considered unlikely. Nevertheless, the vulnerability permits a local attacker with write privileges on a block device to subvert data integrity, which can lead to significant damage if leveraged. The attack vector is local and requires privileged or otherwise trusted access to the underlying storage device; it does not pose a network‑based threat.

Generated by OpenCVE AI on September 19, 2026 at 04:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the fix for dm-integrity as documented in the official patch commit sequence.
  • If a kernel upgrade cannot be performed immediately, disable the allow_discards option or unload the dm-integrity module for the affected volume until a patch is available.
  • Restrict raw write access to the backing device by limiting device node permissions to trusted users or processes, thereby preventing unprivileged write operations.

Generated by OpenCVE AI on September 19, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-275
CWE-286
CWE-615

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-integrity: replace forgeable discard filler with a keyed sector marker The discard-block check in dm_integrity_rw_tag() treats a stored tag of all 0xf6 bytes (DISCARD_FILLER) as proof a block was discarded and skips HMAC verification. allow_discards is only accepted in dm-integrity's standalone mode. An attacker with raw write access to the backing device, but without the integrity key, can stamp any block with an all-0xf6 tag and have it served as authentic. Add a new "allow_discards_keyed" target argument that marks discarded blocks with a keyed checksum of (salt || sector) instead, computed by integrity_discard_checksum().
Title dm-integrity: replace forgeable discard filler with a keyed sector marker
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:46.805Z

Reserved: 2026-09-11T19:38:34.803Z

Link: CVE-2026-90333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:31.830

Modified: 2026-09-17T17:17:31.830

Link: CVE-2026-90333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:45:06Z

Weaknesses
  • CWE-275
  • CWE-286

    Incorrect User Management

  • CWE-615

    Inclusion of Sensitive Information in Source Code Comments