Out-of-bounds read in Linux kernel - CVE-2026-89573
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read out-of-bounds memory.
The vulnerability exists due to improper validation of array block value sizes in dm-array's get_ablock() and __shadow_ablock() functions when processing crafted dm-cache metadata. A local user can cause a mappings array to reference a hint block with a smaller value size to read out-of-bounds memory.