CVE-2026-72101

Summary

In the Linux kernel, the following vulnerability has been resolved:

dm-integrity: fix leaking uninitialized kernel memory

If hash size is less than device's tuple size, dm-integrity is supposed to zero the remaining space. There was a bug in the code that zeroing didn't work. This commit fixes it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxfb0987682c629c1d2c476f35f6fde405a5e304a4 < 50af3e51dc709384701dbc721b4bd865285c5f2caffected
LinuxLinuxfb0987682c629c1d2c476f35f6fde405a5e304a4 < 0c4e9bb1d4101030f55c869f18bd3ece39a77bbbaffected
LinuxLinuxfb0987682c629c1d2c476f35f6fde405a5e304a4 < 8f0af8493009a61b4313e0a8c6e03fbc36fd43f9affected
LinuxLinuxfb0987682c629c1d2c476f35f6fde405a5e304a4 < 7bb03b2b01b814a9fc14afbfc2cbb2cca5b34750affected
LinuxLinux6.11affected
LinuxLinux0 < 6.11unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References