{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89584","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.729Z","datePublished":"2026-09-11T19:44:49.838Z","dateUpdated":"2026-09-13T06:31:17.636Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:31:17.636Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: validate user space vectors during extraction\n\nThe bio-based drivers don't necessarily check the alignment split, and\nstacking block drivers don't always handle a misalignment detected after\nsubmitting the bio. Validate user vectors against the device's\ndma_alignment as the bio is built from the iov_iter, rejecting\nmisaligned early with -EINVAL."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Missing dma_alignment validation is in bio_iov_iter_get_pages()/iov_iter_extract_bvecs(), reached only via local O_DIRECT (preadv/pwritev/io_uring) through blkdev_direct_IO() and iomap_dio_bio_iter_one() on ext4/XFS/btrfs/f2fs or raw block devices; ksmbd/nfsd do not feed attacker-controlled user iovecs into this path.\nAC:L - After the simplified DIO checks, only file offset and total length must be logical-block aligned; the attacker fully controls each iovec address and length and can submit misaligned buffers or io_uring registered buffers deterministically, with no race or attacker-uncontrolled layout required.\nPR:L - Any unprivileged user with read or write access to a regular file on an iomap DIO filesystem, or to a block device they can open, can issue O_DIRECT with no capability; stacked dm/md/LUKS setups are a deployment precondition, not a privilege the attacker must obtain.\nUI:N - The attacker opens their own file or device and issues the misaligned O_DIRECT I/O themselves; no separate victim must mount media, confirm a prompt, or otherwise participate.\nS:U - Impact stays inside the host kernel block layer and stacked devices (invalid DMA, driver mishandling, array denial of service) and does not cross a VM, hypervisor, IOMMU, or sandbox boundary.\nC:H - Bio-based drivers (dm, md) skip __bio_split_to_limits() on normal I/O, so attacker-controlled bvec offsets reach DMA and crypto SG lists such as dm-crypt sg_set_page(). Unaligned or page-crossing DMA, including non-coherent cache-line effects and hardware address rounding, can read adjacent memory.\nI:H - The same unvalidated user vectors are programmed into device DMA and driver scatterlists; misaligned writes, hardware address masking, and cache-line tearing on non-coherent DMA can corrupt adjacent memory or neighboring disk blocks, and drivers that assume aligned bvecs can perform out-of-bounds writes.\nA:H - Misaligned bios are known to degrade md/raid1 and dm-mirror arrays when lower devices return BLK_STS_INVAL, hang dm-io on byte-granular fragments, and can oops or hang bio-based drivers and DMA engines that reject unaligned segments, all kernel-level availability failures."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/bio.c","block/blk-map.c","block/fops.c","fs/iomap/direct-io.c","include/linux/bio.h","include/linux/uio.h","lib/iov_iter.c"],"versions":[{"version":"5ff3f74e145adc79b49668adb8de276446acf6be","lessThan":"d44a97a3b1c00cc571245124e23e5ceb0a0225a0","status":"affected","versionType":"git"},{"version":"5ff3f74e145adc79b49668adb8de276446acf6be","lessThan":"14b007e178811db72fbb1ebb3535160db6ec1e6a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["block/bio.c","block/blk-map.c","block/fops.c","fs/iomap/direct-io.c","include/linux/bio.h","include/linux/uio.h","lib/iov_iter.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d44a97a3b1c00cc571245124e23e5ceb0a0225a0"},{"url":"https://git.kernel.org/stable/c/14b007e178811db72fbb1ebb3535160db6ec1e6a"}],"title":"block: validate user space vectors during extraction","x_generator":{"engine":"bippy-1.2.0"}}}}