Heap-based buffer overflow in Linux kernel - CVE-2026-90052
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a heap-based buffer overflow.
The vulnerability exists due to a heap-based buffer overflow in the integrity_metadata function in drivers/md/dm-integrity.c when processing keyed discard operations with a tag size smaller than the digest size. A local privileged user can issue a keyed discard operation to cause a heap-based buffer overflow.