« Volver al listado

CVE-2026-68478

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

memstick: ms_block: reject a card that reports too many blocks

msb_ftl_initialize() computes the zone count from the card block count with no bound:

msb->block_count is a card value. msb_read_boot_blocks() reads number_of_blocks from the card boot page and byte swaps it. free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the valid indices are 0 to 15.

Leer descripción completaMostrar menos

The init loop above indexes it by zone_count. msb_mark_block_used() and msb_mark_block_unused() index it by pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES * MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past free_block_count[] and corrupts struct msb_data. A larger count runs the init loop past the end too.

A real Memory Stick has at most 16 zones. So it has at most 8192 blocks. msb_ftl_initialize() now rejects a card that reports more than MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.

Detalles técnicos trazas, registros y código del informe original
	msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE;
	...
	for (i = 0; i < msb->zone_count; i++)
		msb->free_block_count[i] = MS_BLOCKS_IN_ZONE;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68478",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "a4b9961efe8640f50800811b4a2b2046b3dc2ccc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "8937b11f1c3896e066c3fb07387ba17bc8c50b8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "f1c675ecf6e5ad02722f0019f729d8bb588d502e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "d5db3439ee8d1c165a09a47e984c4ba508c130df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "b86666ac4009a252501cc17242582a7ec9ed976e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "39151f0708c84221e94cdd6aa070aba5d7cb1c01",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "47f0c7d856c67c9935546d2644f18c0d0131b449",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0ab30494bc4f3bc1ea4659b7c5d97c5218554a63",
              "lessThan": "718178f524b98bc920d74bc771aed823c8b81425",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/memstick/core/ms_block.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/memstick/core/ms_block.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:20:47.573",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemstick: ms_block: reject a card that reports too many blocks\n\nmsb_ftl_initialize() computes the zone count from the card block count\nwith no bound:\n\n\tmsb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE;\n\t...\n\tfor (i = 0; i < msb->zone_count; i++)\n\t\tmsb->free_block_count[i] = MS_BLOCKS_IN_ZONE;\n\nmsb->block_count is a card value. msb_read_boot_blocks() reads\nnumber_of_blocks from the card boot page and byte swaps it.\nfree_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the\nvalid indices are 0 to 15. The init loop above indexes it by zone_count.\nmsb_mark_block_used() and msb_mark_block_unused() index it by\npba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report\nup to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES *\nMS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past\nfree_block_count[] and corrupts struct msb_data. A larger count runs the\ninit loop past the end too.\n\nA real Memory Stick has at most 16 zones. So it has at most 8192 blocks.\nmsb_ftl_initialize() now rejects a card that reports more than\nMS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks."
    }
  ],
  "lastModified": "2026-08-17T06:17:57.333",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}