{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46115","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.098Z","datePublished":"2026-05-28T09:35:26.735Z","dateUpdated":"2026-08-05T12:29:47.285Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:29:47.285Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: add pgmap check to biovec_phys_mergeable\n\nbiovec_phys_mergeable() is used by the request merge, DMA mapping,\nand integrity merge paths to decide if two physically contiguous\nbvec segments can be coalesced into one. It currently has no check\nfor whether the segments belong to different dev_pagemaps.\n\nWhen zone device memory is registered in multiple chunks, each chunk\ngets its own dev_pagemap. A single bio can legitimately contain\nbvecs from different pgmaps -- iov_iter_extract_bvecs() breaks at\npgmap boundaries but the outer loop in bio_iov_iter_get_pages()\ncontinues filling the same bio. If such bvecs are physically\ncontiguous, biovec_phys_mergeable() will coalesce them, making it\nimpossible to recover the correct pgmap for the merged segment\nvia page_pgmap().\n\nAdd a zone_device_pages_have_same_pgmap() check to prevent merging\nbvec segments that span different pgmaps."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - Reachable via remotely-initiated NVMe-oF (nvmet-tcp/nvmet-rdma) I/O on a P2PDMA-backed namespace; remote read/write commands drive the block-layer merge/SG-mapping path (`biovec_phys_mergeable`) over P2P buffers on the target.\nAC:L - Adjacent chunks of multi-chunk P2P/zone-device memory are physically contiguous, so the missing pgmap check makes the bad coalesce occur deterministically once such memory backs the I/O; repeated/large I/O reliably straddles a pgmap boundary.\nPR:N - NVMe-oF targets are commonly deployed without in-band cryptographic authentication, so a connected (unauthenticated) initiator can issue the I/O that reaches the vulnerable path.\nUI:N - Exploitation requires only that the attacker issue normal I/O commands; no victim/administrator interaction is needed.\nS:U - The corruption stays within the kernel's own block/DMA handling and adjacent device memory; it does not cross into a separately-managed security authority such as a VM host.\nC:H - A misdirected DMA on a read maps the spillover pages to the wrong pgmap's bus address, so data from unrelated device memory can be returned to the attacker — an arbitrary-read/disclosure-class primitive.\nI:H - A misdirected DMA on a write transfers data to the wrong physical/device address, corrupting unrelated device or host memory — an out-of-bounds write primitive.\nA:H - Wrong/invalid DMA bus addresses cause IOMMU faults, device errors, and kernel oops/hangs, crashing the I/O path or the system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk.h"],"versions":[{"version":"49580e690755d0e51ed7aa2c33225dd884fa738a","lessThan":"3d2ecbd444b01d6500671d1a582b7393943cf539","status":"affected","versionType":"git"},{"version":"49580e690755d0e51ed7aa2c33225dd884fa738a","lessThan":"a7f3aa8c9df3905fe820ae36b67ba56b81587574","status":"affected","versionType":"git"},{"version":"49580e690755d0e51ed7aa2c33225dd884fa738a","lessThan":"f17d521075325b8afc42d1baa1c28a5e9aca111f","status":"affected","versionType":"git"},{"version":"49580e690755d0e51ed7aa2c33225dd884fa738a","lessThan":"f632dab4b841554cd6416058c61886d7db176581","status":"affected","versionType":"git"},{"version":"49580e690755d0e51ed7aa2c33225dd884fa738a","lessThan":"13920e4b7b784b40cf4519ff1f0f3e513476a499","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/blk.h"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.88","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.12.88"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.18.30"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.0.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3d2ecbd444b01d6500671d1a582b7393943cf539"},{"url":"https://git.kernel.org/stable/c/a7f3aa8c9df3905fe820ae36b67ba56b81587574"},{"url":"https://git.kernel.org/stable/c/f17d521075325b8afc42d1baa1c28a5e9aca111f"},{"url":"https://git.kernel.org/stable/c/f632dab4b841554cd6416058c61886d7db176581"},{"url":"https://git.kernel.org/stable/c/13920e4b7b784b40cf4519ff1f0f3e513476a499"}],"title":"block: add pgmap check to biovec_phys_mergeable","x_generator":{"engine":"bippy-1.2.0"}}}}