SB20260816499 - Out-of-bounds write in Linux kernel ata driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-72030)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in ata_dev_config_cpr() and the VPD page B9h emitter when processing a device-reported concurrent positioning ranges log. An attacker with physical access can connect a crafted device that reports an invalid concurrent positioning ranges count to cause a denial of service.
The issue can affect both parsing of the returned log data and emission of one descriptor per range into a fixed-size response buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4c1e8ccd8655ee8cf1bcb1b7dfee72c9fa941fd4
- https://git.kernel.org/stable/c/4cb4b4dd8853c4ab3057efe238b2c34277772176
- https://git.kernel.org/stable/c/533a0b940f901c15e5cbbd4b5d66e871c209e8ce
- https://git.kernel.org/stable/c/b1607f0ee5f5e53e0aa66f41794085b7cc98f5d1
- https://git.kernel.org/stable/c/d43efd1b5d976203e6f1ef26f67e8b1a7bc2751b