CVE-2026-80710
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/08/2026
Última modificación:
28/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/dasd: Fix undersized format-check buffer<br />
<br />
fmt_buffer_size in dasd_eckd_check_device_format() is declared as<br />
int, even though one of the multiplicands, sizeof(struct eckd_count),<br />
is a size_t. The expression<br />
<br />
trkcount * rpt_max * sizeof(struct eckd_count)<br />
<br />
is therefore correctly evaluated at 64-bit width, but the result is<br />
silently truncated when it is stored back into the 32-bit<br />
fmt_buffer_size variable. For a sufficiently large track range<br />
(start_unit/stop_unit are caller-controlled) this truncation<br />
yields a buffer size far smaller than the number of tracks actually<br />
requested. kzalloc() then succeeds with an undersized allocation,<br />
while the subsequent channel program build still operates on the<br />
untruncated track count and writes past the end of that buffer.<br />
<br />
Compute the buffer size with check_mul_overflow() and keep it in a<br />
size_t, so that a value that no longer fits results in -EINVAL<br />
instead of a silently truncated allocation size.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/7f40b346462f563a0d6e841a77b5163d2a882a04
- https://git.kernel.org/stable/c/87f3389cd3920714c53e704778f7ca7f1cf0c39c
- https://git.kernel.org/stable/c/9f88dda2f22927d22498801a92cab6a9424eaf86
- https://git.kernel.org/stable/c/aca18289c86f22d3fc2f3f6ff615286e7b1702f6
- https://git.kernel.org/stable/c/e16e0fc54120cee3c6f0362de95aab6792865857



