CVE-2026-46294

In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony Asleson (using Claude) found a buffer overflow in dm-ioctl in the function retrieve_status: 1. The code in retrieve_status checks that the output string fits into the output buffer and writes the output string there 2. Then, the code aligns the "outptr" variable to the next 8-byte boundary: outptr = align_ptr(outptr); 3. The alignment doesn't check overflow, so outptr could point past the buffer end 4. The "for" loop is iterated again, it executes: remaining = len - (outptr - outbuf); 5. If "outptr" points past "outbuf + len", the arithmetics wraps around and the variable "remaining" contains unusually high number 6. With "remaining" being high, the code writes more data past the end of the buffer Luckily, this bug has no security implications because: 1. Only root can issue device mapper ioctls 2. The commonly used libraries that communicate with device mapper (libdevmapper and devicemapper-rs) use buffer size that is aligned to 8 bytes - thus, "outptr = align_ptr(outptr)" can't overshoot the input buffer and the bug can't happen accidentally
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: dm: corrige un desbordamiento de búfer en el procesamiento de ioctl Tony Asleson (usando Claude) encontró un desbordamiento de búfer en dm-ioctl en la función retrieve_status: 1. El código en retrieve_status verifica que la cadena de salida cabe en el búfer de salida y escribe la cadena de salida allí 2. Luego, el código alinea la variable 'outptr' al siguiente límite de 8 bytes: outptr = align_ptr(outptr); 3. La alineación no verifica el desbordamiento, por lo que 'outptr' podría apuntar más allá del final del búfer 4. El bucle 'for' se itera de nuevo, ejecuta: remaining = len - (outptr - outbuf); 5. Si 'outptr' apunta más allá de 'outbuf + len', la aritmética se desborda y la variable 'remaining' contiene un número inusualmente alto 6. Siendo 'remaining' alto, el código escribe más datos más allá del final del búfer Afortunadamente, este error no tiene implicaciones de seguridad porque: 1. Solo root puede emitir ioctls del mapeador de dispositivos 2. Las bibliotecas comúnmente utilizadas que se comunican con el mapeador de dispositivos (libdevmapper y devicemapper-rs) usan un tamaño de búfer que está alineado a 8 bytes; por lo tanto, 'outptr = align_ptr(outptr)' no puede exceder el búfer de entrada y el error no puede ocurrir accidentalmente

08 Jul 2026, 19:04

Type Values Removed Values Added
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/2fa49cc884f6496a915c35621ba4da35649bf159 - () https://git.kernel.org/stable/c/2fa49cc884f6496a915c35621ba4da35649bf159 - Patch
References () https://git.kernel.org/stable/c/448ee8fb79c26a26599ffa4b2adeb4322d3d3d8c - () https://git.kernel.org/stable/c/448ee8fb79c26a26599ffa4b2adeb4322d3d3d8c - Patch
References () https://git.kernel.org/stable/c/526ff9126a0ae087b65726e1faf31114c718020d - () https://git.kernel.org/stable/c/526ff9126a0ae087b65726e1faf31114c718020d - Patch
References () https://git.kernel.org/stable/c/5af6a879e915ae7bcd83695c316ebb32e1c61bc2 - () https://git.kernel.org/stable/c/5af6a879e915ae7bcd83695c316ebb32e1c61bc2 - Patch
References () https://git.kernel.org/stable/c/8daa6c708ef524089ae43f2aed9190acb26d7df8 - () https://git.kernel.org/stable/c/8daa6c708ef524089ae43f2aed9190acb26d7df8 - Patch
References () https://git.kernel.org/stable/c/c8c5311237448f6ffeecc9aec2362e3692623668 - () https://git.kernel.org/stable/c/c8c5311237448f6ffeecc9aec2362e3692623668 - Patch
References () https://git.kernel.org/stable/c/d271631023cbe1cbe7c31a0275ab797883be6e0a - () https://git.kernel.org/stable/c/d271631023cbe1cbe7c31a0275ab797883be6e0a - Patch
References () https://git.kernel.org/stable/c/f0b0b09d9840838ae77ccdd6a62de0daef4e6e0a - () https://git.kernel.org/stable/c/f0b0b09d9840838ae77ccdd6a62de0daef4e6e0a - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
CWE CWE-787

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46294

Mitre link : CVE-2026-46294

CVE.ORG link : CVE-2026-46294


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write