-

CVE-2026-68478

memstick: ms_block: reject a card that reports too many blocks

In the Linux kernel, the following vulnerability has been resolved:

memstick: ms_block: reject a card that reports too many blocks

msb_ftl_initialize() computes the zone count from the card block count
with no bound:

	msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE;
	...
	for (i = 0; i < msb->zone_count; i++)
		msb->free_block_count[i] = MS_BLOCKS_IN_ZONE;

msb->block_count is a card value. msb_read_boot_blocks() reads
number_of_blocks from the card boot page and byte swaps it.
free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the
valid indices are 0 to 15. The init loop above indexes it by zone_count.
msb_mark_block_used() and msb_mark_block_unused() index it by
pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report
up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES *
MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past
free_block_count[] and corrupts struct msb_data. A larger count runs the
init loop past the end too.

A real Memory Stick has at most 16 zones. So it has at most 8192 blocks.
msb_ftl_initialize() now rejects a card that reports more than
MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < a4b9961efe8640f50800811b4a2b2046b3dc2ccc
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < 8937b11f1c3896e066c3fb07387ba17bc8c50b8a
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < f1c675ecf6e5ad02722f0019f729d8bb588d502e
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < d5db3439ee8d1c165a09a47e984c4ba508c130df
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < b86666ac4009a252501cc17242582a7ec9ed976e
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < 39151f0708c84221e94cdd6aa070aba5d7cb1c01
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < 47f0c7d856c67c9935546d2644f18c0d0131b449
Status affected
Version 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Version < 718178f524b98bc920d74bc771aed823c8b81425
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.12
Status affected
Version 0
Version < 3.12
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.115
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc
https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a
https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e
https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df
https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e
https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01
https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449
https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425