CVE-2026-68478: memstick: ms_block: reject a card that reports too many blocks

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081506-CVE-2026-68478-8b6c@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

memstick: ms_block: reject a card that reports too many blocks

msb_ftl_initialize() computes the zone count from the card block count
with no bound:

	msb->zone_count = msb->block_count / MS_BLOCKS_IN_ZONE;
	...
	for (i = 0; i < msb->zone_count; i++)
		msb->free_block_count[i] = MS_BLOCKS_IN_ZONE;

msb->block_count is a card value. msb_read_boot_blocks() reads
number_of_blocks from the card boot page and byte swaps it.
free_block_count is a fixed int[MS_MAX_ZONES]. MS_MAX_ZONES is 16, so the
valid indices are 0 to 15. The init loop above indexes it by zone_count.
msb_mark_block_used() and msb_mark_block_unused() index it by
pba / MS_BLOCKS_IN_ZONE, for pba up to block_count - 1. A card may report
up to 65535 blocks. A block_count above 8192 (MS_MAX_ZONES *
MS_BLOCKS_IN_ZONE) lets the pba index reach 16. That writes past
free_block_count[] and corrupts struct msb_data. A larger count runs the
init loop past the end too.

A real Memory Stick has at most 16 zones. So it has at most 8192 blocks.
msb_ftl_initialize() now rejects a card that reports more than
MS_MAX_ZONES * MS_BLOCKS_IN_ZONE blocks.

The Linux kernel CVE team has assigned CVE-2026-68478 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 5.10.261 with commit a4b9961efe8640f50800811b4a2b2046b3dc2ccc
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 5.15.212 with commit 8937b11f1c3896e066c3fb07387ba17bc8c50b8a
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.1.178 with commit f1c675ecf6e5ad02722f0019f729d8bb588d502e
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.6.145 with commit d5db3439ee8d1c165a09a47e984c4ba508c130df
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.12.97 with commit b86666ac4009a252501cc17242582a7ec9ed976e
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 6.18.40 with commit 39151f0708c84221e94cdd6aa070aba5d7cb1c01
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 7.1.5 with commit 47f0c7d856c67c9935546d2644f18c0d0131b449
	Issue introduced in 3.12 with commit 0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 and fixed in 7.2-rc4 with commit 718178f524b98bc920d74bc771aed823c8b81425

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68478
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/memstick/core/ms_block.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/a4b9961efe8640f50800811b4a2b2046b3dc2ccc
	https://git.kernel.org/stable/c/8937b11f1c3896e066c3fb07387ba17bc8c50b8a
	https://git.kernel.org/stable/c/f1c675ecf6e5ad02722f0019f729d8bb588d502e
	https://git.kernel.org/stable/c/d5db3439ee8d1c165a09a47e984c4ba508c130df
	https://git.kernel.org/stable/c/b86666ac4009a252501cc17242582a7ec9ed976e
	https://git.kernel.org/stable/c/39151f0708c84221e94cdd6aa070aba5d7cb1c01
	https://git.kernel.org/stable/c/47f0c7d856c67c9935546d2644f18c0d0131b449
	https://git.kernel.org/stable/c/718178f524b98bc920d74bc771aed823c8b81425
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.