CVE-2026-46289
In the Linux kernel, the following vulnerability has been resolved:
lib/scatterlist: fix length calculations in extract_kvec_to_sg
Patch series "Fix bugs in extract_iter_to_sg()", v3.
Fix bugs in the kvec and user variants of extract_iter_to_sg. This series is growing due to useful remarks made by sashiko.dev.
The series adds test cases to the kunit_iov_iter test that demonstrate all of these bugs. Additionally, there is a memory leak fix for the test itself.
The bugs were orignally introduced into kernel v6.3 where the function lived in fs/netfs/iterator.c. It was later moved to lib/scatterlist.c in v6.5. Thus the actual fix is only marked for backports to v6.5+.
Leer descripción completaMostrar menos
This patch (of 5):
When extracting from a kvec to a scatterlist, do not cross page boundaries. The required length was already calculated but not used as intended.
Adjust the copied length if the loop runs out of sglist entries without extracting everything.
While there, return immediately from extract_iter_to_sg if there are no sglist entries at all.
A subsequent commit will add kunit test cases that demonstrate that the patch is necessary.
Detalles técnicos trazas, registros y código del informe original
The main bugs are: - The length for an sglist entry when extracting from a kvec can exceed the number of bytes in the page. This is obviously not intended. - When extracting a user buffer the sglist is temporarily used as a scratch buffer for extracted page pointers. If the sglist already contains some elements this scratch buffer could overlap with existing entries in the sglist.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 50
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 %
Vulnerabilidad remota sin autenticación (AV:N/PR:N/UI:N) en el kernel Linux que permite causar DoS mediante corrupción de memoria en scatterlist. Acceso crítico a confidencialidad e integridad.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-401
Referencias
- https://git.kernel.org/stable/c/07b7d66e65d9cfe6b9c2c34aa22cfcaac37a5c45
- https://git.kernel.org/stable/c/3f17500e86d730c76db638bb3ae52f9b5e496c76
- https://git.kernel.org/stable/c/8fbba6829057979149d1b37d65690c037f3ddf4d
- https://git.kernel.org/stable/c/9d38756d0a93b66163554219fa9c3365f40c4035
- https://git.kernel.org/stable/c/e5e22fc9963469e678c4f4bb38d26adcec107f1e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46289",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0185846975339a5c348373aa450a977f5242366b",
"lessThan": "3f17500e86d730c76db638bb3ae52f9b5e496c76",
"versionType": "git"
},
{
"status": "affected",
"version": "0185846975339a5c348373aa450a977f5242366b",
"lessThan": "e5e22fc9963469e678c4f4bb38d26adcec107f1e",
"versionType": "git"
},
{
"status": "affected",
"version": "0185846975339a5c348373aa450a977f5242366b",
"lessThan": "8fbba6829057979149d1b37d65690c037f3ddf4d",
"versionType": "git"
},
{
"status": "affected",
"version": "0185846975339a5c348373aa450a977f5242366b",
"lessThan": "9d38756d0a93b66163554219fa9c3365f40c4035",
"versionType": "git"
},
{
"status": "affected",
"version": "0185846975339a5c348373aa450a977f5242366b",
"lessThan": "07b7d66e65d9cfe6b9c2c34aa22cfcaac37a5c45",
"versionType": "git"
}
],
"programFiles": [
"lib/scatterlist.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"lib/scatterlist.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-08T17:16:47.097",
"references": [
{
"url": "https://git.kernel.org/stable/c/07b7d66e65d9cfe6b9c2c34aa22cfcaac37a5c45",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3f17500e86d730c76db638bb3ae52f9b5e496c76",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8fbba6829057979149d1b37d65690c037f3ddf4d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9d38756d0a93b66163554219fa9c3365f40c4035",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e5e22fc9963469e678c4f4bb38d26adcec107f1e",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/scatterlist: fix length calculations in extract_kvec_to_sg\n\nPatch series \"Fix bugs in extract_iter_to_sg()\", v3.\n\nFix bugs in the kvec and user variants of extract_iter_to_sg. This series\nis growing due to useful remarks made by sashiko.dev.\n\nThe main bugs are:\n- The length for an sglist entry when extracting from\n a kvec can exceed the number of bytes in the page. This\n is obviously not intended.\n- When extracting a user buffer the sglist is temporarily\n used as a scratch buffer for extracted page pointers.\n If the sglist already contains some elements this scratch\n buffer could overlap with existing entries in the sglist.\n\nThe series adds test cases to the kunit_iov_iter test that demonstrate all\nof these bugs. Additionally, there is a memory leak fix for the test\nitself.\n\nThe bugs were orignally introduced into kernel v6.3 where the function\nlived in fs/netfs/iterator.c. It was later moved to lib/scatterlist.c in\nv6.5. Thus the actual fix is only marked for backports to v6.5+.\n\n\nThis patch (of 5):\n\nWhen extracting from a kvec to a scatterlist, do not cross page\nboundaries. The required length was already calculated but not used as\nintended.\n\nAdjust the copied length if the loop runs out of sglist entries without\nextracting everything.\n\nWhile there, return immediately from extract_iter_to_sg if there are no\nsglist entries at all.\n\nA subsequent commit will add kunit test cases that demonstrate that the\npatch is necessary."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nlib/scatterlist: corrige los cálculos de longitud en extract_kvec_to_sg\n\nSerie de parches 'Corrige errores en extract_iter_to_sg()', v3.\n\nCorrige errores en las variantes kvec y de usuario de extract_iter_to_sg. Esta serie está creciendo debido a comentarios útiles hechos por sashiko.dev.\n\nLos principales errores son:\n- La longitud para una entrada de sglist al extraer de un kvec puede exceder el número de bytes en la página. Esto obviamente no está previsto.\n- Al extraer un búfer de usuario, el sglist se utiliza temporalmente como un búfer temporal para punteros de página extraídos. Si el sglist ya contiene algunos elementos, este búfer temporal podría superponerse con entradas existentes en el sglist.\n\nLa serie añade casos de prueba a la prueba kunit_iov_iter que demuestran todos estos errores. Además, hay una corrección de fuga de memoria para la propia prueba.\n\nLos errores fueron introducidos originalmente en el kernel v6.3 donde la función residía en fs/netfs/iterator.c. Posteriormente fue movida a lib/scatterlist.c en v6.5. Por lo tanto, la corrección real solo está marcada para backports a v6.5+.\n\nEste parche (de 5):\n\nAl extraer de un kvec a un scatterlist, no cruzar los límites de página. La longitud requerida ya estaba calculada pero no se usó como se pretendía.\n\nAjustar la longitud copiada si el bucle se queda sin entradas de sglist sin extraer todo.\n\nMientras tanto, regresar inmediatamente de extract_iter_to_sg si no hay ninguna entrada de sglist en absoluto.\n\nUn commit posterior añadirá casos de prueba kunit que demuestran que el parche es necesario."
}
],
"lastModified": "2026-07-23T08:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE397E0D-B39E-43DA-B546-2C72385DF22F",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AFBE0EC-CCDF-4207-AE92-ABF958125CA4",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF39AE08-AE6D-4410-8FBE-76F6BF5BF55B",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0893CA7-9AE6-4DFE-AC75-48967D73AD8E",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}