Always-Incorrect Control Flow Implementation in Linux kernel - CVE-2026-46115
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of dev_pagemap boundaries in biovec_phys_mergeable() when coalescing physically contiguous bvec segments. A local user can trigger merging of segments from different dev_pagemaps to cause a denial of service.
The issue occurs when a bio contains bvecs from different dev_pagemaps that are physically contiguous.
How to mitigate CVE-2026-46115
Sources
- https://git.kernel.org/stable/c/13920e4b7b784b40cf4519ff1f0f3e513476a499
- https://git.kernel.org/stable/c/3d2ecbd444b01d6500671d1a582b7393943cf539
- https://git.kernel.org/stable/c/a7f3aa8c9df3905fe820ae36b67ba56b81587574
- https://git.kernel.org/stable/c/f17d521075325b8afc42d1baa1c28a5e9aca111f
- https://git.kernel.org/stable/c/f632dab4b841554cd6416058c61886d7db176581