7.8

CVE-2026-89559

libnvdimm/labels: Prevent integer overflow in __nd_label_validate()

In the Linux kernel, the following vulnerability has been resolved:

libnvdimm/labels: Prevent integer overflow in __nd_label_validate()

The on-media namespace index field nslot is a u32 read from the DIMM
label storage area.  __nd_label_validate() bounds it against the config
area size, but sizeof_namespace_label() returns unsigned, so the product
nslot * label_size is evaluated in 32-bit and wraps modulo 2^32 before
the comparison.  A crafted nslot passes the bound and is then used as the
loop trip count in nd_label_data_init(), whose memset() walks off the end
of the config_size buffer: an out-of-bounds write.

The field is not trusted -- it comes from the medium, or from userspace
via ND_CMD_SET_CONFIG_DATA.  Evaluate the product in 64-bit so the bound
check is exact; conforming labels are unaffected.

The check was safe when introduced by commit 4a826c83db4e ("libnvdimm:
namespace indices: read and validate"): it multiplied by sizeof(struct
nd_namespace_label), a size_t, so on a 64-bit build the product did not
wrap.  Commit 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label
definitions") narrowed it to 32 bits when the label size became a runtime
value read via sizeof_namespace_label().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < b4975f2ff6c82adc24ae547f029f82530ba43cfe
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 6030597ec683d1e5b46445f888bb5c7776b5a0c4
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 1c391696d2791f82ae462e11da9a0d96f90b240c
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 93967bfb17dab66642c57e609c99e1a91fe11278
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < e057efcc9c71d90099d9ee00bed0748d0e9fd586
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 09e649117c54b7e1c004f22eaa19efbadd9ac856
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 69a734359639fca16a0dd73ab17a34943e76c68b
Status affected
Version 564e871aa66f548a947b23808d3140f326381f0c
Version < 037770686126155eafc44501312989e2837b9659
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.13
Status affected
Version 0
Version < 4.13
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e057efcc9c71d90099d9ee00bed0748d0e9fd586
https://git.kernel.org/stable/c/09e649117c54b7e1c004f22eaa19efbadd9ac856
https://git.kernel.org/stable/c/69a734359639fca16a0dd73ab17a34943e76c68b
https://git.kernel.org/stable/c/037770686126155eafc44501312989e2837b9659
https://git.kernel.org/stable/c/1c391696d2791f82ae462e11da9a0d96f90b240c
https://git.kernel.org/stable/c/6030597ec683d1e5b46445f888bb5c7776b5a0c4
https://git.kernel.org/stable/c/93967bfb17dab66642c57e609c99e1a91fe11278
https://git.kernel.org/stable/c/b4975f2ff6c82adc24ae547f029f82530ba43cfe