CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the integrity handling of bio structures, specifically in the bio_integrity_copy_user() function, where improper management of the bip_vcnt variable can lead to out-of-bounds reads. This flaw may allow an attacker to exploit the gap-merge checks, potentially leading to unauthorized access to sensitive data. Organizations using affected Linux systems should prioritize patching this vulnerability to mitigate the risk of data exposure.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: block: don't overwrite bip_vcnt in bio_integrity_copy_user() bio_integrity_add_page() already sets bip_vcnt to 1 for the bounce segment. Overwriting it with nr_vecs breaks bip_vcnt <= bip_max_vcnt on WRITE (bip_max_vcnt is 1), so the gap-merge checks in block/blk.h read past the bip_vec[] flex array. On READ the read is in bounds but lands on a saved user bvec instead of the bounce. The line was added for split propagation, but bio_integrity_clone() doesn't copy bip_vcnt and BIP_CLONE_FLAGS excludes BIP_COPY_USER.