PT-2026-90275 · Linux · Linux
CVE-2026-89559
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
libnvdimm/labels: Prevent integer overflow in nd label validate()
The on-media namespace index field nslot is a u32 read from the DIMM
label storage area. nd label validate() bounds it against the config
area size, but sizeof namespace label() returns unsigned, so the product
nslot * label size is evaluated in 32-bit and wraps modulo 2^32 before
the comparison. A crafted nslot passes the bound and is then used as the
loop trip count in nd label data init(), whose memset() walks off the end
of the config size buffer: an out-of-bounds write.
The field is not trusted -- it comes from the medium, or from userspace
via ND CMD SET CONFIG DATA. Evaluate the product in 64-bit so the bound
check is exact; conforming labels are unaffected.
The check was safe when introduced by commit 4a826c83db4e ("libnvdimm:
namespace indices: read and validate"): it multiplied by sizeof(struct
nd namespace label), a size t, so on a 64-bit build the product did not
wrap. Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label
definitions") narrowed it to 32 bits when the label size became a runtime
value read via sizeof namespace label().
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux