Linux dm_log OOB write due to region_count overflow
CVE-2026-53059 Published on June 24, 2026
dm log: fix out-of-bounds write due to region_count overflow
In the Linux kernel, the following vulnerability has been resolved:
dm log: fix out-of-bounds write due to region_count overflow
The local variable region_count in create_log_context() is declared as
unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).
When a device-mapper target has a sufficiently large ti->len with a small
region_size, the division result can exceed UINT_MAX. The truncated
value is then used to calculate bitset_size, causing clean_bits,
sync_bits, and recovering_bits to be allocated far smaller than needed
for the actual number of regions.
Subsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use
region indices derived from the full untruncated region space, causing
out-of-bounds writes to kernel heap memory allocated by vmalloc.
This can be reproduced by creating a mirror target whose region_count
overflows 32 bits:
dmsetup create bigzero --table '0 8589934594 zero'
dmsetup create mymirror --table '0 8589934594 mirror \
core 2 2 nosync 2 /dev/mapper/bigzero 0 \
/dev/mapper/bigzero 0'
The status output confirms the truncation (sync_count=1 instead of
4294967297, because 0x100000001 was truncated to 1):
$ dmsetup status mymirror
0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...
This leads to a kernel crash in core_in_sync:
BUG: scheduling while atomic: (udev-worker)/9150/0x00000000
RIP: 0010:core_in_sync+0x14/0x30 [dm_log]
CR2: 0000000000000008
Fixing recursive fault but reboot is needed!
Fix by widening the local region_count to sector_t and adding an
explicit overflow check before the value is assigned to lc->region_count.
Vulnerability Analysis
CVE-2026-53059 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a high impact on availability.
Weakness Type
Integer Overflow or Wraparound
The software performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control. An integer overflow or wraparound occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may wrap to become a very small or negative number. While this may be intended behavior in circumstances that rely on wrapping, it can have security consequences if the wrap is unexpected. This is especially the case if the integer overflow can be triggered using user-supplied inputs. This becomes security-critical when the result is used to control looping, make a security decision, or determine the offset or size in behaviors such as memory allocation, copying, concatenation, etc.
Products Associated with CVE-2026-53059
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-53059 are published in these products:
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 44ab8875ae4a2842bde2d756bed195d375e0debb is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below defe483e47173768c227532694dc78cb65db5f09 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 3ec74da927b4e171a6fc0e77b1188ba4d019af51 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below d4ac87567f86a55c3c92e9a5144dcd943a9772a1 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 12bd5b88e91a02785244ff1d20fb157e96e9cdc8 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below b455903eed4558982be0811f5b7f44f6bbc4ff57 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 4ec8323b9f0764a14d532b1ae9b87f8a9fecb867 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below c20e36b7631d83e7535877f08af8b0af72c44b1a is affected.
- Version 2.6.12 is affected.
- Before 2.6.12 is unaffected.
- Version 5.10.258, <= 5.10.* is unaffected.
- Version 5.15.209, <= 5.15.* is unaffected.
- Version 6.1.175, <= 6.1.* is unaffected.
- Version 6.6.141, <= 6.6.* is unaffected.
- Version 6.12.91, <= 6.12.* is unaffected.
- Version 6.18.33, <= 6.18.* is unaffected.
- Version 7.0.10, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.
- Version 0:6.12.0-211.39.1.el10_2 and below * is unaffected.
- Version 0:4.18.0-553.147.1.rt7.488.el8_10 and below * is unaffected.
- Version 0:4.18.0-553.147.1.el8_10 and below * is unaffected.
- Version 0:4.18.0-305.200.1.el8_4 and below * is unaffected.
- Version 0:4.18.0-305.200.1.el8_4 and below * is unaffected.
- Version 0:5.14.0-687.30.1.el9_8 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.