CVE-2026-89578
Received Received - Intake

dm-io Memory Corruption in Linux Kernel

Vulnerability report for CVE-2026-89578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: dm-io: clone the source bio instead of copying its biovec For DM_IO_BIO requests, do_region() built each destination bio by walking the source bio's biovec and re-adding the pages one at a time, tracking the remaining transfer in sectors. The vector lengths are byte granular and need not be sector aligned (e.g. a misaligned O_DIRECT buffer split across pages), so the sector-based accounting could lose a sub-sector fragment: to_sector() truncated the remainder and the outer loop spun forever submitting empty bios, hanging the I/O. There is no need to rebuild the biovec at all. The destination reads into (or writes from) exactly the same pages as the source bio, so the bio can simply clone the source's biovec with bio_alloc_clone() and remap it to the target device. The clone inherits the source's iterator and alignment, and the block layer splits it to the target's limits on submission, so the whole region maps to a single cloned bio with no manual page copying or sector accounting. This removes the per-page copy path (and its open-coded bvec dpages helpers) for bio-backed I/O and fixes the hang on misaligned direct I/O to a dm-mirror device. Page-list, vma and kmem sources keep the existing copy path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the device mapper (dm-io) component where the system incorrectly handles bio requests. The issue occurs when the source bio's biovec (a structure describing data segments) is copied incorrectly, leading to an infinite loop of empty bio submissions. This happens because sector-based accounting fails to account for byte-granular vector lengths, causing the system to hang during I/O operations.

Detection Guidance

This vulnerability is specific to the Linux kernel's device mapper (dm-io) and may cause system hangs during misaligned direct I/O operations. Detection requires checking kernel logs for I/O hangs or system freezes, particularly when using dm-mirror devices. No direct commands are provided in the context, but monitoring for system hangs or checking kernel logs for related errors may help identify this issue.

Impact Analysis

This vulnerability can cause system hangs or crashes during I/O operations, particularly when using direct I/O to a dm-mirror device with misaligned buffers. This may lead to data corruption, application failures, or system unavailability, disrupting normal operations.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel I/O handling issue causing system hangs due to misaligned direct I/O operations. Compliance impacts would only occur if the vulnerability led to data corruption, unauthorized access, or service disruptions affecting protected data.

Mitigation Strategies

Apply the latest Linux kernel patches that address this vulnerability. Since the issue is resolved in the kernel, updating to a patched version will mitigate the risk. Avoid using misaligned O_DIRECT buffers with dm-mirror devices until the patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart