AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72107

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's dm-era component, which improperly handles out-of-bounds memory access due to incorrect calculations of write-set blocks when a non-zero start sector is used. This flaw can lead to potential memory corruption, exposing systems to stability issues or unauthorized access. System administrators and developers working with Linux kernel configurations that utilize dm-era should prioritize applying the relevant patches to mitigate this risk.

CVE
CVE-2026-72107
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory access for non-zero start sector dm-era tracks writes in target-relative blocks, but era_map() calculates the writeset block before applying the target offset. Tables with a non-zero start sector can therefore pass an absolute mapped-device block to metadata_current_marked(). If the absolute block is beyond the current writeset size, writeset_marked() tests past the end of the in-core bitset. KASAN reports this as a vmalloc-out-of-bounds access. Apply the target offset before calculating the era block so writeset lookups use the target-relative block number.