CVE-2026-19617
Received Received - Intake

Stack Overflow in libdm LVM Metadata Parser

Vulnerability report for CVE-2026-19617, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Red Hat, Inc.

Description

A flaw was found in libdm. A remote attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat lvm2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in libdm, part of the Logical Volume Manager (LVM). A remote attacker can create a malicious LVM metadata configuration with deeply nested structures. When parsed, this causes uncontrolled recursion in the libdm configuration file parser, exhausting the stack and crashing any LVM command that reads the metadata. This leads to a Denial of Service (DoS) on affected systems.

Detection Guidance

Monitor for crashes in LVM commands or system hangs when processing metadata. Check logs for stack exhaustion errors in libdm. Use vulnerability scanners like Red Hat's tools to detect affected LVM2 versions.

Impact Analysis

If exploited, this vulnerability can cause system crashes when LVM commands process malicious metadata. This results in a Denial of Service, making the system unavailable for legitimate use. Systems relying on LVM for storage management are particularly affected.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) by crashing LVM commands through stack exhaustion, which could disrupt system availability. For compliance standards like GDPR or HIPAA, which require data availability and system reliability, such disruptions may violate availability requirements. However, the provided context does not explicitly link this vulnerability to specific compliance violations or data breaches.

Mitigation Strategies

Avoid processing untrusted LVM metadata files. Apply vendor patches if available. Restrict access to LVM configuration files. Monitor for unusual system resource usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart