7.8

CVE-2026-64053

block: don't overwrite bip_vcnt in bio_integrity_copy_user()

In the Linux kernel, the following vulnerability has been resolved:

block: don't overwrite bip_vcnt in bio_integrity_copy_user()

bio_integrity_add_page() already sets bip_vcnt to 1 for the bounce
segment. Overwriting it with nr_vecs breaks bip_vcnt <= bip_max_vcnt
on WRITE (bip_max_vcnt is 1), so the gap-merge checks in block/blk.h
read past the bip_vec[] flex array. On READ the read is in bounds
but lands on a saved user bvec instead of the bounce.

The line was added for split propagation, but bio_integrity_clone()
doesn't copy bip_vcnt and BIP_CLONE_FLAGS excludes BIP_COPY_USER.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 3991657ae7074c3c497bf095093178bed37ea1b4
Version < d18160c9525c63c203656fefd847e94b538cd4a4
Status affected
Version 3991657ae7074c3c497bf095093178bed37ea1b4
Version < 0d48654af4d1390c888389206cc13b51b82c30e6
Status affected
Version 3991657ae7074c3c497bf095093178bed37ea1b4
Version < 066be1439593a381b1a29663becfcfe0c92363e7
Status affected
Version 3991657ae7074c3c497bf095093178bed37ea1b4
Version < 637ad3a56a3b889527d1dacea6fea2a8bd648140
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.92
Status unaffected
Version <= 6.18.*
Version 6.18.34
Status unaffected
Version <= 7.0.*
Version 7.0.11
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d18160c9525c63c203656fefd847e94b538cd4a4
https://git.kernel.org/stable/c/0d48654af4d1390c888389206cc13b51b82c30e6
https://git.kernel.org/stable/c/066be1439593a381b1a29663becfcfe0c92363e7
https://git.kernel.org/stable/c/637ad3a56a3b889527d1dacea6fea2a8bd648140