Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-80710

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/08/2026
Última modificación:
28/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> s390/dasd: Fix undersized format-check buffer<br /> <br /> fmt_buffer_size in dasd_eckd_check_device_format() is declared as<br /> int, even though one of the multiplicands, sizeof(struct eckd_count),<br /> is a size_t. The expression<br /> <br /> trkcount * rpt_max * sizeof(struct eckd_count)<br /> <br /> is therefore correctly evaluated at 64-bit width, but the result is<br /> silently truncated when it is stored back into the 32-bit<br /> fmt_buffer_size variable. For a sufficiently large track range<br /> (start_unit/stop_unit are caller-controlled) this truncation<br /> yields a buffer size far smaller than the number of tracks actually<br /> requested. kzalloc() then succeeds with an undersized allocation,<br /> while the subsequent channel program build still operates on the<br /> untruncated track count and writes past the end of that buffer.<br /> <br /> Compute the buffer size with check_mul_overflow() and keep it in a<br /> size_t, so that a value that no longer fits results in -EINVAL<br /> instead of a silently truncated allocation size.

Impacto