Out-of-bounds read in Linux kernel - CVE-2026-89574
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to read beyond the dm-bufio buffer.
The vulnerability exists due to improper validation of on-disk array block headers in the dm-array component when loading dm-cache mappings from on-disk array blocks. A local user can cause dm_cache_load_mappings() to process an array block header whose entry count exceeds its capacity to read beyond the dm-bufio buffer.
The vulnerable path is reached during dm-cache activation.