SB2026082859 - Integer overflow in Linux kernel s390 block driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-80710)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow leading to an undersized allocation in dasd_eckd_check_device_format() when processing caller-controlled track ranges. A local user can provide a sufficiently large start and stop unit range to trigger a buffer overflow and cause a denial of service.
The issue occurs because the computed buffer size is truncated before allocation, while subsequent operations use the full untruncated track count.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7f40b346462f563a0d6e841a77b5163d2a882a04
- https://git.kernel.org/stable/c/87f3389cd3920714c53e704778f7ca7f1cf0c39c
- https://git.kernel.org/stable/c/9f88dda2f22927d22498801a92cab6a9424eaf86
- https://git.kernel.org/stable/c/aca18289c86f22d3fc2f3f6ff615286e7b1702f6
- https://git.kernel.org/stable/c/e16e0fc54120cee3c6f0362de95aab6792865857