{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89573","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.727Z","datePublished":"2026-09-11T19:44:41.851Z","dateUpdated":"2026-09-14T12:01:06.500Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:06.500Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndm array: reject an array block whose value size is not the caller's\n\narray_block_check() can only compare the header against itself, so a block\nwith value_size 4 and max_entries 1018 is internally consistent and passes.\ndm-cache keeps two arrays -- mappings at 8 bytes and hints at 4 -- and the\nroots for both live in the superblock. Point the mappings root at a hint\nblock and __load_mappings() walks it through an info whose value size is 8,\nso element_at() strides 8 bytes over 4-byte entries and reaches offset 8160\nof a 4096-byte block.\n\nget_ablock() and __shadow_ablock() are the two places that hold the block\nand the caller at once. Reject there when the two value sizes disagree.\nArrays only ever read their own blocks, so this fires on crafted metadata\nonly."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached when device-mapper loads crafted dm-cache/dm-era array metadata through the local DM ioctl path (table load and resume) or LVM autoactivation of a cache/era target; it is not processed from network packets or a USB host/gadget driver.\nAC:L - The attacker fully controls the on-disk superblock roots and array headers, so pointing the 8-byte mappings root at a valid 4-byte hint block makes __load_mappings() deterministically stride off the 4096-byte bufio buffer; no race or layout outside the attacker's control is required.\nPR:L - Planting the metadata only requires write access to the cache/era backing store (loop file, removable disk, iSCSI/NBD, or a container/VM-exposed block device), not init-namespace CAP_SYS_ADMIN on /dev/mapper/control; user namespaces cannot pass capable(CAP_SYS_ADMIN), but an unprivileged writer of that store is enough.\nUI:N - Activation of a dm-cache/dm-era target is routine device management (udev/LVM autoactivation, boot, or reattachment of the metadata device) and does not require a separate victim to mount a filesystem or otherwise opt in once the crafted metadata is in place.\nS:U - The out-of-bounds access stays inside kernel dm-bufio metadata buffers and cache policy state in the same kernel security authority; it is not a VM escape, IOMMU bypass, or other cross-authority boundary.\nC:H - element_at() multiplies the caller's value size by the on-disk nr_entries, so the cursor reads thousands of bytes past the 4K dm-bufio page (offset 8160 of a 4096-byte block), leaking adjacent kernel memory into mapping, hint, and bitset values.\nI:H - The type-confused walk treats attacker-controlled hint bytes as 8-byte mappings and can shadow/fill the wrong-sized block, corrupting cache policy and subsequent origin/cache writeback; this is kernel memory unsafety with an out-of-bounds/type-confused write primitive, so integrity is high.\nA:H - Walking off the mapped 4K bufio page into unmapped or invalid memory oopses the kernel, and a mismatched on-disk nr_entries versus the caller's max_entries can hit BUG_ON() in fill_ablock()/trim_ablock() on resize."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/persistent-data/dm-array.c"],"versions":[{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"35cd3b278448c79614f65ab6bbc9ed348d847df9","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"a8237cb8fa0a628d903e76635bfdeae4202036b9","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"a530a9a419a7c5fdb7dae55ffa2dd7a130631842","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"522fa26da24ccaa298ebe3c1c97395d2d63dfc21","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"7bf4b5cb42a4e27f36bcbc6209d82a5da9c0168c","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"ac4a5eb8b002a0742c938fc98b922e243f53573a","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"cb409b38b0232ee4385ef55cddcd6fbdd011a8a2","status":"affected","versionType":"git"},{"version":"6513c29f44f2cc970c0e9fecfe5a6526c3e73025","lessThan":"4538a287bdf5d0f9a379c678e5262b9f5783f547","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/md/persistent-data/dm-array.c"],"versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/35cd3b278448c79614f65ab6bbc9ed348d847df9"},{"url":"https://git.kernel.org/stable/c/a8237cb8fa0a628d903e76635bfdeae4202036b9"},{"url":"https://git.kernel.org/stable/c/a530a9a419a7c5fdb7dae55ffa2dd7a130631842"},{"url":"https://git.kernel.org/stable/c/522fa26da24ccaa298ebe3c1c97395d2d63dfc21"},{"url":"https://git.kernel.org/stable/c/7bf4b5cb42a4e27f36bcbc6209d82a5da9c0168c"},{"url":"https://git.kernel.org/stable/c/ac4a5eb8b002a0742c938fc98b922e243f53573a"},{"url":"https://git.kernel.org/stable/c/cb409b38b0232ee4385ef55cddcd6fbdd011a8a2"},{"url":"https://git.kernel.org/stable/c/4538a287bdf5d0f9a379c678e5262b9f5783f547"}],"title":"dm array: reject an array block whose value size is not the caller's","x_generator":{"engine":"bippy-1.2.0"}}}}