{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-46130", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-05-13T15:03:33.099Z", "datePublished": "2026-05-28T09:35:45.387Z", "dateUpdated": "2026-08-03T09:32:32.606Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-03T09:32:32.606Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-verity-fec: fix reading parity bytes split across blocks (take 3)\n\nfec_decode_bufs() assumes that the parity bytes of the first RS codeword\nit decodes are never split across parity blocks.\n\nThis assumption is false. Consider v->fec->block_size == 4096 &&\nv->fec->roots == 17 && fio->nbufs == 1, for example. In that case, each\ncall to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs <<\nDM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.\n\nConsidering that the parity data for each message block starts on a\nblock boundary, the byte alignment in the parity data will iterate\nthrough 272*i mod 4096 until the 3 parity blocks have been consumed. On\nthe 16th call (i=15), the alignment will be 4080 bytes into the first\nblock. Only 16 bytes remain in that block, but 17 parity bytes will be\nneeded. The code reads out-of-bounds from the parity block buffer.\n\nFortunately this doesn't normally happen, since it can occur only for\ncertain non-default values of fec_roots *and* when the maximum number of\nbuffers couldn't be allocated due to low memory. For example with\nblock_size=4096 only the following cases are affected:\n\n fec_roots=17: nbufs in [1, 3, 5, 15]\n fec_roots=19: nbufs in [1, 229]\n fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]\n fec_roots=23: nbufs in [1, 89]\n\nRegardless, fix it by refactoring how the parity blocks are read." } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/md/dm-verity-fec.c" ], "versions": [ { "version": "6df90c02bae468a3a6110bafbc659884d0c4966c", "lessThan": "d47281b9a4472cfd73122393e79fbe76b651e46a", "status": "affected", "versionType": "git" }, { "version": "6df90c02bae468a3a6110bafbc659884d0c4966c", "lessThan": "3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb", "status": "affected", "versionType": "git" }, { "version": "6df90c02bae468a3a6110bafbc659884d0c4966c", "lessThan": "430a05cb926f6bdf53e81460a2c3a553257f3f61", "status": "affected", "versionType": "git" }, { "version": "6bc6ee31113b05db605694491bdeb2b1730142f1", "status": "affected", "versionType": "git" }, { "version": "12caa73a28f0ae147ec0356b45091edf2462462b", "status": "affected", "versionType": "git" }, { "version": "fc8943886629e26de34867db302c74d465510826", "status": "affected", "versionType": "git" }, { "version": "6.1.125", "lessThan": "6.2", "status": "affected", "versionType": "semver" }, { "version": "6.6.72", "lessThan": "6.7", "status": "affected", "versionType": "semver" }, { "version": "6.12.10", "lessThan": "6.13", "status": "affected", "versionType": "semver" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/md/dm-verity-fec.c" ], "versions": [ { "version": "6.13", "status": "affected" }, { "version": "0", "lessThan": "6.13", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.42", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0.7", "lessThanOrEqual": "7.0.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "6.18.42" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "7.0.7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.13", "versionEndExcluding": "7.1" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.1.125" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.6.72" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.12.10" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/d47281b9a4472cfd73122393e79fbe76b651e46a" }, { "url": "https://git.kernel.org/stable/c/3d1b4e2d8ac0a1a1390a117f61ce0ca1c47e3bcb" }, { "url": "https://git.kernel.org/stable/c/430a05cb926f6bdf53e81460a2c3a553257f3f61" } ], "title": "dm-verity-fec: fix reading parity bytes split across blocks (take 3)", "x_generator": { "engine": "bippy-1.2.0" } } } }