CVE-2026-89584

Summary

In the Linux kernel, the following vulnerability has been resolved:

block: validate user space vectors during extraction

The bio-based drivers don't necessarily check the alignment split, and stacking block drivers don't always handle a misalignment detected after submitting the bio. Validate user vectors against the device's dma_alignment as the bio is built from the iov_iter, rejecting misaligned early with -EINVAL.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux5ff3f74e145adc79b49668adb8de276446acf6be < d44a97a3b1c00cc571245124e23e5ceb0a0225a0affected
LinuxLinux5ff3f74e145adc79b49668adb8de276446acf6be < 14b007e178811db72fbb1ebb3535160db6ec1e6aaffected
LinuxLinux6.18affected
LinuxLinux0 < 6.18unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References