PT-2026-94681 · Linux · Linux Kernel

CVE-2026-90333

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the dm-integrity component where the dm integrity rw tag() function treats a stored tag consisting of all 0xf6 bytes (DISCARD FILLER) as evidence that a block was discarded, leading it to skip HMAC (Hash-based Message Authentication Code) verification. When allow discards is enabled in standalone mode, an attacker with raw write access to the backing device can bypass integrity checks by marking any block with the 0xf6 tag, causing the system to treat the forged block as authentic even without the integrity key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102681
CVE-2026-90333
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel