In the Linux kernel, the following vulnerability has been resolved:
dm mirror: fix integer overflow in create_dirty_log()
The argument count calculation in create_dirty_log() performs
`*args_used = 2 + param_count` before validating against argc. When a
user provides a param_count close to UINT_MAX via the device mapper
table string, this unsigned addition wraps around to a small value,
causing the subsequent `argc < *args_used` check to be bypassed.
The overflowed param_count is then passed as argc to dm_dirty_log_create(),
where it can cause out-of-bounds reads on the argv array.
Fix by comparing param_count against argc - 2 before performing the
addition, following the same pattern used by parse_features() in the
same file. Since argc >= 2 is already guaranteed, the subtraction is
safe.
References
Configurations
Configuration 1 (hide)
|
History
16 Jun 2026, 15:55
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Linux linux Kernel
Linux |
|
| References | () https://git.kernel.org/stable/c/17a08791d428885d00e510864283a7b839792368 - Patch | |
| References | () https://git.kernel.org/stable/c/249c831183fb806c8e3b14c7c4c1d2fb68cf37fb - Patch | |
| References | () https://git.kernel.org/stable/c/35f6b3281efd44d19110574663bc17a610bc73b9 - Patch | |
| References | () https://git.kernel.org/stable/c/47dad9eea75d33212d3d2cea10e7ed6a1bfc0713 - Patch | |
| References | () https://git.kernel.org/stable/c/4c788c6f921b22f9b6c3f316c4a071c05683e7de - Patch | |
| References | () https://git.kernel.org/stable/c/87c99a50e0fdc68a5b9b52a94d49452cd3ff02ca - Patch | |
| References | () https://git.kernel.org/stable/c/ae59b3025609d5a0a39cf5b2b94e2467f6231573 - Patch | |
| References | () https://git.kernel.org/stable/c/e5e0ae3237584ebef510366c4cb3d5cc7c22b610 - Patch | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* |
|
| CWE | CWE-190 |
01 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
27 May 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 14:17
Updated : 2026-06-17 10:52
NVD link : CVE-2026-46023
Mitre link : CVE-2026-46023
CVE.ORG link : CVE-2026-46023
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-190
Integer Overflow or Wraparound
