Out-of-bounds read in Linux kernel - CVE-2026-46070
Published: May 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() when processing corrupted journal metadata blocks. A local user can provide a corrupted journal with payload size fields that extend beyond the metadata block boundary to disclose sensitive information.
How to mitigate CVE-2026-46070
Sources
- https://git.kernel.org/stable/c/33698bd1b2db9764a29df7751533d33967ff5c98
- https://git.kernel.org/stable/c/406aa86394ead347c47428fb51b6359bdaa2257d
- https://git.kernel.org/stable/c/73ce72edd113374801045924d4417199963f73a3
- https://git.kernel.org/stable/c/b0cc3ae97e893bf54bbce447f4e9fd2e0b88bff9
- https://git.kernel.org/stable/c/c3a1cf78bd1bbb51b2cc5189b4743056553c1e0e